This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Laptop Freezes for Minutes at a Time [Closed]

64 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-09-18 10:56:56
—————————–
10:56:56.079    OS Version: Windows x64 6.1.7601 Service Pack 1
10:56:56.079    Number of processors: 4 586 0x4501
10:56:56.079    ComputerName: SRELAB-HP  UserName: SRE Lab
10:56:56.672    Initialize success
11:00:24.705    AVAST engine defs: 15091801
11:00:45.652    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000009a
11:00:45.652    Disk 0 Vendor: HGST GH2O Size: 476940MB BusType: 11
11:00:45.777    Disk 0 MBR read successfully
11:00:45.777    Disk 0 MBR scan
11:00:45.793    Disk 0 Windows 7 default MBR code
11:00:45.793    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS         1025 MB offset 2048
11:00:45.793    Disk 0 default boot code
11:00:45.808    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       462140 MB offset 2101248
11:00:45.840    Disk 0 Partition 3 00     07    HPFS/NTFS NTFS        11721 MB offset 948563968
11:00:45.855    Disk 0 Partition 4 00     0B        FAT32 MSDOS5.0     2048 MB offset 972568576
11:00:45.886    Disk 0 scanning C:\Windows\system32\drivers
11:00:55.293    Service scanning
11:01:17.086    Modules scanning
11:01:17.086    Disk 0 trace - called modules:
11:01:17.118    ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys iaStorF.sys storport.sys hal.dll iaStorA.sys 
11:01:17.133    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800a169060]
11:01:17.133    3 CLASSPNP.SYS[fffff8800102943f] -> nt!IofCallDriver -> [0xfffffa8007d59950]
11:01:17.133    5 hpdskflt.sys[fffff8800273642b] -> nt!IofCallDriver -> [0xfffffa8007d558b0]
11:01:17.164    7 iaStorF.sys[fffff88002721ab0] -> nt!IofCallDriver -> \Device\0000009a[0xfffffa80078eb9c0]
11:01:17.695    AVAST engine scan C:\Windows
11:01:19.582    AVAST engine scan C:\Windows\system32
11:03:52.371    AVAST engine scan C:\Windows\system32\drivers
11:04:04.805    AVAST engine scan C:\Users\SRE Lab
11:06:15.933    AVAST engine scan C:\ProgramData
11:06:45.356    Disk 0 statistics 3809159/0/0 @ 8.64 MB/s
11:06:45.356    Scan finished successfully
11:07:38.494    Disk 0 MBR has been saved successfully to "C:\Users\SRE Lab\Desktop\MBR.dat"
11:07:38.494    The log file has been saved successfully to "C:\Users\SRE Lab\Desktop\aswMBR.txt"
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:15-09-2015
Ran by [removed] (administrator) on SRELAB-HP (18-09-2015 11:16:09)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286056 2013-07-30] (Intel Corporation)
HKLM\…\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1703424 2013-07-04] (IDT, Inc.)
HKLM\…\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.exe [7032320 2013-09-30] (Broadcom Corporation)
HKLM\…\Run: [] => [X]
HKLM\…\Run: [CryptoMill Refresh] => C:\Program Files\Hewlett-Packard\HP Trust Circles\ceflauncher -m refresh
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2774256 2013-08-19] (Synaptics Incorporated)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.)
HKLM-x32\…\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [683656 2013-07-18] (PDF Complete Inc)
HKLM-x32\…\Run: [HPConnectionManager] => c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [185144 2013-08-15] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [337184 2013-07-31] (Hewlett-Packard Company)
HKLM-x32\…\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation)
HKLM-x32\…\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [77088 2013-07-24] (Hewlett-Packard Company)
HKLM-x32\…\Run: [YouCam Mirage] => c:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488 2013-06-24] (CyberLink)
HKLM-x32\…\Run: [YouCam Tray] => c:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe [167488 2013-06-24] (CyberLink Corp.)
HKLM-x32\…\Run: [HP File Sanitizer] => C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\Coreshredder.exe [2213592 2013-08-07] (Hewlett-Packard)
HKLM-x32\…\Run: [mcpltui_exe] => C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe [719272 2015-04-02] (McAfee, Inc.)
HKLM-x32\…\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
HKLM\…\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe,
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\…\Policies\Explorer: [NoFolderOptions] 0
HKLM\…\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\…\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\…\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CORESHREDDER.exe [2213592 2013-08-07] (Hewlett-Packard)
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\…\RunOnce: [Application Restart #1] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944 2015-08-27] (Google Inc.)
AppInit_DLLs: C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => No File
AppInit_DLLs-x32: C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll => No File
Lsa: [Notification Packages] DPPassFilter scecli c:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
ShellIconOverlayIdentifiers: [+1TBIcon] -> {B9C55E85-DED6-4911-82F3-83CF1CAB2898} => C:\Program Files\Hewlett-Packard\HP Trust Circles\tbicon.dll [2013-08-22] (CryptoMill Technologies Ltd.)
ShellIconOverlayIdentifiers-x32: [+1TBIcon] -> {B9C55E85-DED6-4911-82F3-83CF1CAB2898} => C:\Program Files (x86)\Hewlett-Packard\HP Trust Circles\tbicon.dll [2013-08-22] (CryptoMill Technologies Ltd.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2013-09-30]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ISCTSystray.lnk [2013-09-30]
ShortcutTarget: ISCTSystray.lnk -> C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe (Intel Corporation)
Startup: C:\Users\SRE Lab\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PowerReg Scheduler.exe [2014-09-23] ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.150.1
Tcpip\..\Interfaces\{74926853-863F-4080-A8D2-B951833BED4F}: [DhcpNameServer] 192.168.150.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCOM14/1
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCOM14/1
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCOM14/1
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-08-12] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-21] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-07-14] (Microsoft Corporation)
BHO-x32: HP File Sanitizer -> {3134413B-49B4-425C-98A5-893C1F195601} -> C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2013-08-07] (Hewlett-Packard)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-08-12] (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-07-14] (Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2012-07-09] (Hewlett-Packard)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\program files\mcafee\msc\mcsniepl64.dll [2015-04-07] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\program files (x86)\mcafee\msc\mcsniepl.dll [2015-04-07] (McAfee, Inc.)
 
FireFox:
========
FF Plugin: @mcafee.com/MSC,version=10 -> c:\program files\mcafee\msc\npmcsnffpl64.dll [2015-04-07] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1215155.dll [2014-12-02] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-07-25] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-07-25] (Intel Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\program files (x86)\mcafee\msc\npmcsnffpl.dll [2015-04-07] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-03-31] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-28] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Plugin-x32: digitalpersona.com/ChromeDPAgent -> C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\ChromeExt\components\npChromeDPAgent.dll [2013-08-05] (DigitalPersona, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-03-31] (Microsoft Corporation)
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt
FF Extension: DigitalPersona Extension - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt [2013-09-30]
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://google.com/"
CHR Profile: C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-12]
CHR Extension: (Google Docs) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-12]
CHR Extension: (Google Drive) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-12]
CHR Extension: (YouTube) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-12]
CHR Extension: (Google Search) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-12]
CHR Extension: (Google Sheets) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-12]
CHR Extension: (Google Docs Offline) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-02]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13]
CHR Extension: (DigitalPersona Extension) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncffjdbbodifgldkcbhmiiljfcnbgjab [2014-09-12]
CHR Extension: (Chrome Web Store Payments) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-12]
CHR Extension: (Gmail) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-12]
CHR HKLM-x32\…\Chrome\Extension: [ncffjdbbodifgldkcbhmiiljfcnbgjab] - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\ChromeExt\dpchrome.crx [2013-08-05]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
S2 CreoService; C:\Program Files (x86)\Hewlett-Packard\HP Trust Circles\CreoSvc.exe [1366488 2013-08-22] (CryptoMill Technologies Ltd.)
S2 CtAgentService; C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe [7168 2013-08-07] () [File not signed]
S2 DpHost; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [500048 2013-08-05] (DigitalPersona, Inc.)
S3 FLCDLOCK; c:\Windows\SysWOW64\flcdlock.exe [558392 2013-08-06] (Hewlett-Packard Company)
S2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc.)
S2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-06-07] (Hewlett-Packard Company) [File not signed]
S2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe [681760 2013-07-31] (Hewlett-Packard Company)
S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [14696 2013-07-30] (Intel Corporation)
S2 Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
S2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-07-25] (Intel Corporation)
S2 ISCTAgent; c:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [197608 2013-07-22] ()
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-07-25] (Intel Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [753768 2015-04-07] (McAfee, Inc.)
S2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.5.450.0\McCSPServiceHost.exe [207344 2015-04-08] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc.)
S2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [612688 2015-04-09] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc.)
S2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [232656 2015-02-17] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [372144 2015-04-06] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [250672 2015-02-17] (McAfee, Inc.)
S2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1143432 2013-07-18] (PDF Complete Inc)
S2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [337920 2013-07-04] (IDT, Inc.) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
S2 wltrysvc; C:\Program Files\Broadcom\Broadcom 802.11\bcmwltry.exe [5878272 2013-09-30] (Broadcom Corporation) [File not signed]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [165688 2012-09-24] (Broadcom Corporation.)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [68784 2015-02-17] (McAfee, Inc.)
S3 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [65752 2013-06-13] (Hewlett-Packard Company)
R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [488216 2014-02-28] (Intel Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [28008 2013-07-30] (Intel Corporation)
S3 IceKore; C:\Windows\System32\DRIVERS\IceKore.sys [397784 2013-08-19] (CryptoMill Technologies Inc.)
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [21408 2013-07-22] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [21920 2013-07-22] ()
S3 INETMON; C:\Windows\System32\Drivers\INETMON.sys [29088 2013-07-22] ()
R3 ISCT; C:\Windows\system32\drivers\ISCTD64.sys [46568 2013-07-22] ()
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-09-13] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-12-19] (Intel Corporation)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [401736 2015-02-17] (McAfee, Inc.)
S3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [337888 2015-02-17] (McAfee, Inc.)
R0 mfedisk; C:\Windows\System32\DRIVERS\mfedisk.sys [101872 2015-02-17] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [488000 2015-02-17] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [864072 2015-02-17] (McAfee, Inc.)
S3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [482600 2015-01-16] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [100720 2015-01-16] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [340448 2015-02-17] (McAfee, Inc.)
R0 PinFile; C:\Windows\System32\DRIVERS\PinFile.sys [49856 2013-07-16] (WinMagic Inc.)
S3 RTSPER; C:\Windows\System32\DRIVERS\RtsPer.sys [427736 2013-08-09] (Realsil Semiconductor Corporation)
R0 SDDisk2K; C:\Windows\System32\DRIVERS\SDDisk2K.sys [228544 2013-07-16] (WinMagic Inc.)
R0 SDDToki; C:\Windows\System32\DRIVERS\SDDToki.sys [131264 2013-07-16] (WinMagic Inc.)
S3 SmbDrv; C:\Windows\system32\drivers\Smb_driver_AMDASF.sys [30448 2013-08-19] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\system32\drivers\Smb_driver_Intel.sys [34544 2013-08-19] (Synaptics Incorporated)
S3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [1512568 2013-06-25] (Sunplus)
U3 aswMBR; \??\C:\Users\SRE Lab\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\SRE Lab\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-18 11:16 - 2015-09-18 11:16 - 00021445 _____ C:\Users\SRE Lab\Desktop\FRST.txt
2015-09-18 11:15 - 2015-09-18 11:16 - 00000000 ____D C:\FRST
2015-09-18 11:09 - 2015-09-18 11:14 - 02191360 _____ (Farbar) C:\Users\SRE Lab\Desktop\FRST64.exe
2015-09-18 11:07 - 2015-09-18 11:07 - 00002306 _____ C:\Users\SRE Lab\Desktop\aswMBR.txt
2015-09-18 11:07 - 2015-09-18 11:07 - 00000512 _____ C:\Users\SRE Lab\Desktop\MBR.dat
2015-09-18 10:54 - 2015-09-18 10:55 - 05198336 _____ (AVAST Software) C:\Users\SRE Lab\Desktop\aswMBR.exe
2015-09-18 10:25 - 2015-09-18 10:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2015-09-13 19:36 - 2015-09-13 20:26 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-09-13 19:35 - 2015-09-13 19:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-09-13 19:35 - 2015-09-13 19:35 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-09-13 19:35 - 2015-09-13 19:35 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-09-13 19:35 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-09-13 19:35 - 2015-06-18 08:41 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-09-13 19:35 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-09-13 19:32 - 2015-09-13 19:34 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\SRE Lab\Downloads\mbam-setup-2.1.8.1057 (1).exe
2015-09-13 19:32 - 2015-09-13 19:33 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\SRE Lab\Downloads\mbam-setup-2.1.8.1057.exe
2015-09-13 18:43 - 2015-09-13 18:43 - 00003280 ____N C:\bootsqm.dat
2015-09-10 08:24 - 2015-09-10 08:24 - 00010731 _____ C:\Users\SRE Lab\Downloads\meeting.collab
2015-09-10 08:24 - 2015-09-10 08:24 - 00010731 _____ C:\Users\SRE Lab\Downloads\meeting (1).collab
2015-09-09 23:48 - 2015-09-09 23:48 - 00008432 _____ C:\Users\SRE Lab\Downloads\work_room (1).collab
2015-09-09 23:45 - 2015-09-09 23:46 - 00000000 ____D C:\Users\SRE Lab\AppData\Roaming\Blackboard
2015-09-09 23:39 - 2015-09-09 23:39 - 00000000 ____D C:\Users\SRE Lab\AppData\Local\Blackboard
2015-09-09 22:53 - 2015-09-13 19:16 - 00000000 __SHD C:\Windows\SysWOW64\AI_RecycleBin
2015-09-09 15:19 - 2015-08-17 18:42 - 00393304 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-09-09 15:19 - 2015-08-17 18:14 - 00344168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-09-09 15:19 - 2015-08-14 23:48 - 25190400 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-09-09 15:19 - 2015-08-14 23:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-09-09 15:19 - 2015-08-14 23:33 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-09-09 15:19 - 2015-08-14 23:18 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-09-09 15:19 - 2015-08-14 23:18 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-09-09 15:19 - 2015-08-14 23:17 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-09-09 15:19 - 2015-08-14 23:17 - 00585216 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-09-09 15:19 - 2015-08-14 23:17 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-09-09 15:19 - 2015-08-14 23:17 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-09-09 15:19 - 2015-08-14 23:10 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-09-09 15:19 - 2015-08-14 23:09 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-09-09 15:19 - 2015-08-14 23:06 - 19856896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-09-09 15:19 - 2015-08-14 23:06 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-09-09 15:19 - 2015-08-14 23:04 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-09-09 15:19 - 2015-08-14 23:04 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-09-09 15:19 - 2015-08-14 23:04 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-09-09 15:19 - 2015-08-14 23:04 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-09-09 15:19 - 2015-08-14 23:00 - 05923328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-09-09 15:19 - 2015-08-14 22:57 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-09-09 15:19 - 2015-08-14 22:53 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-09-09 15:19 - 2015-08-14 22:53 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-09-09 15:19 - 2015-08-14 22:46 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-09-09 15:19 - 2015-08-14 22:42 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-09-09 15:19 - 2015-08-14 22:41 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-09-09 15:19 - 2015-08-14 22:40 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-09-09 15:19 - 2015-08-14 22:40 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-09-09 15:19 - 2015-08-14 22:39 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-09-09 15:19 - 2015-08-14 22:39 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-09-09 15:19 - 2015-08-14 22:39 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-09-09 15:19 - 2015-08-14 22:38 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-09-09 15:19 - 2015-08-14 22:35 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-09-09 15:19 - 2015-08-14 22:33 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-09-09 15:19 - 2015-08-14 22:32 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-09-09 15:19 - 2015-08-14 22:30 - 00479232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-09-09 15:19 - 2015-08-14 22:29 - 00665600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-09-09 15:19 - 2015-08-14 22:29 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-09-09 15:19 - 2015-08-14 22:29 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-09-09 15:19 - 2015-08-14 22:24 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-09-09 15:19 - 2015-08-14 22:23 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-09-09 15:19 - 2015-08-14 22:22 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-09-09 15:19 - 2015-08-14 22:22 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-09-09 15:19 - 2015-08-14 22:21 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-09-09 15:19 - 2015-08-14 22:16 - 14451712 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-09-09 15:19 - 2015-08-14 22:16 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-09-09 15:19 - 2015-08-14 22:14 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-09-09 15:19 - 2015-08-14 22:12 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-09-09 15:19 - 2015-08-14 22:11 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-09-09 15:19 - 2015-08-14 22:10 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-09-09 15:19 - 2015-08-14 22:07 - 02427392 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-09-09 15:19 - 2015-08-14 22:04 - 12857344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-09-09 15:19 - 2015-08-14 22:02 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-09-09 15:19 - 2015-08-14 22:01 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-09-09 15:19 - 2015-08-14 22:01 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-09-09 15:19 - 2015-08-14 21:55 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-09-09 15:19 - 2015-08-14 21:43 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-09-09 15:19 - 2015-08-14 21:43 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-09-09 15:19 - 2015-08-14 21:39 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-09-09 15:19 - 2015-08-14 21:37 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-09-09 15:19 - 2015-08-05 10:56 - 01110016 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2015-09-09 15:19 - 2015-07-14 20:17 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-09-09 15:19 - 2015-07-14 19:54 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2015-09-09 15:19 - 2015-07-09 10:58 - 01632256 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-09-09 15:19 - 2015-07-09 10:58 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2015-09-09 15:19 - 2015-07-09 10:42 - 01372160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-09-09 15:19 - 2015-07-09 10:42 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2015-09-09 15:14 - 2015-08-27 11:18 - 02004480 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-09-09 15:14 - 2015-08-27 11:18 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-09-09 15:14 - 2015-08-27 11:13 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2015-09-09 15:14 - 2015-08-27 11:13 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-09-09 15:14 - 2015-08-27 10:58 - 01391104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2015-09-09 15:14 - 2015-08-27 10:58 - 01241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-09-09 15:14 - 2015-08-27 10:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2015-09-09 15:14 - 2015-08-27 10:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2015-09-09 15:14 - 2015-06-25 03:06 - 00115136 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-09-09 15:14 - 2015-06-25 03:01 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-09-09 15:14 - 2015-06-25 03:01 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2015-09-09 15:14 - 2015-06-25 02:44 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-09-09 15:13 - 2015-09-01 20:04 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-09-09 15:13 - 2015-09-01 20:04 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-09-09 15:13 - 2015-09-01 20:04 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-09-09 15:13 - 2015-09-01 20:04 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-09-09 15:13 - 2015-09-01 19:48 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-09-09 15:13 - 2015-09-01 19:48 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-09-09 15:13 - 2015-09-01 19:48 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-09-09 15:13 - 2015-09-01 19:47 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-09-09 15:13 - 2015-09-01 18:51 - 03209216 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-09-09 15:13 - 2015-09-01 18:47 - 00372736 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-09-09 15:13 - 2015-09-01 18:33 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-09-09 15:12 - 2015-08-26 11:07 - 03165696 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-09-09 15:12 - 2015-08-26 11:07 - 02606080 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-09-09 15:12 - 2015-08-26 11:07 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-09-09 15:12 - 2015-08-26 11:07 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-09-09 15:12 - 2015-08-26 11:07 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-09-09 15:12 - 2015-08-26 11:07 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-09-09 15:12 - 2015-08-26 11:07 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-09-09 15:12 - 2015-08-26 11:06 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-09-09 15:12 - 2015-08-26 11:06 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-09-09 15:12 - 2015-08-26 11:06 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-09-09 15:12 - 2015-08-26 11:06 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-09-09 15:12 - 2015-08-26 10:56 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-09-09 15:12 - 2015-08-26 10:56 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-09-09 15:12 - 2015-08-26 10:56 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-09-09 15:12 - 2015-08-26 10:56 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-09-09 15:12 - 2015-08-26 10:55 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-09-06 12:53 - 2015-09-06 12:54 - 25482411 _____ C:\Users\SRE Lab\Desktop\The infiltrator.mp4
2015-09-01 13:50 - 2015-09-01 13:50 - 00002095 _____ C:\Users\Public\Desktop\Zoo Tycoon.lnk
2015-09-01 13:50 - 2015-09-01 13:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
2015-09-01 13:33 - 2015-09-01 13:33 - 00001336 _____ C:\Users\SRE Lab\Desktop\LEGO Racers.lnk
2015-08-31 15:16 - 2015-09-01 12:59 - 00000000 ____D C:\Users\SRE Lab\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-08-31 15:07 - 2015-08-31 15:07 - 00000000 ____D C:\Program Files (x86)\Microsoft Games
2015-08-27 16:15 - 2015-08-27 16:16 - 00271113 _____ C:\Users\SRE Lab\Downloads\pac-man.zip
2015-08-27 13:12 - 2015-08-27 13:13 - 20822282 _____ C:\Users\SRE Lab\Desktop\THe Trashie strongarm.mp4
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-18 10:23 - 2009-07-13 22:13 - 00805126 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-14 10:54 - 2013-09-08 21:35 - 00000000 ____D C:\ProgramData\PDFC
2015-09-14 10:53 - 2014-09-12 10:03 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-14 10:53 - 2013-09-08 21:35 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-09-14 10:53 - 2009-07-13 21:51 - 00107142 _____ C:\Windows\setupact.log
2015-09-14 10:52 - 2013-09-30 10:13 - 00000225 _____ C:\Windows\CryptoMill_CreoService.log
2015-09-14 10:52 - 2013-09-08 21:35 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-09-14 10:52 - 2009-07-13 22:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-14 07:23 - 2009-07-13 21:45 - 00026832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-09-14 07:20 - 2009-07-13 21:45 - 00026832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-09-14 06:53 - 2013-09-30 10:13 - 00000225 _____ C:\Windows\CryptoMill_CreoService.001
2015-09-14 06:53 - 2009-07-13 21:45 - 00433064 _____ C:\Windows\system32\FNTCACHE.DAT
2015-09-14 06:51 - 2013-10-24 10:28 - 01312624 _____ C:\Windows\WindowsUpdate.log
2015-09-14 06:51 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-09-14 06:44 - 2014-09-12 10:03 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-14 06:35 - 2014-09-12 11:24 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-09-14 06:35 - 2014-09-12 11:20 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-09-14 06:33 - 2014-09-11 13:39 - 00000000 ____D C:\Windows\system32\MRT
2015-09-14 06:25 - 2009-07-13 19:34 - 00000580 _____ C:\Windows\win.ini
2015-09-13 20:33 - 2013-09-30 10:13 - 00000225 _____ C:\Windows\CryptoMill_CreoService.002
2015-09-13 20:25 - 2013-09-30 10:13 - 00000225 _____ C:\Windows\CryptoMill_CreoService.003
2015-09-13 20:25 - 2010-11-20 20:47 - 00317134 _____ C:\Windows\PFRO.log
2015-09-13 20:03 - 2013-09-30 10:13 - 00000225 _____ C:\Windows\CryptoMill_CreoService.004
2015-09-13 19:17 - 2015-07-25 10:07 - 00000000 ____D C:\Users\SRE Lab\AppData\Local\Unity
2015-09-13 19:16 - 2014-09-12 06:29 - 00000000 ____D C:\Windows\system32\appmgmt
2015-09-13 19:06 - 2013-09-30 10:13 - 00000225 _____ C:\Windows\CryptoMill_CreoService.005
2015-09-13 18:39 - 2015-02-28 21:43 - 00000000 ____D C:\Users\SRE Lab\AppData\Local\Intel_Corporation
2015-09-13 15:08 - 2013-10-24 10:27 - 00003938 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{DD9B90AE-3AD8-4A15-A8BB-9A1EB32D171F}
2015-09-13 14:54 - 2014-09-14 15:54 - 00000000 ____D C:\Users\SRE Lab\AppData\Local\CrashDumps
2015-09-11 11:44 - 2014-10-13 20:30 - 00000000 ____D C:\Users\SRE Lab\Documents\Outlook Files
2015-09-10 16:46 - 2014-09-12 10:03 - 00000000 ____D C:\Users\SRE Lab\AppData\Local\Google
2015-09-06 13:57 - 2015-05-16 17:11 - 00000000 ____D C:\Users\SRE Lab\Desktop\Dawn Of War
2015-09-05 18:30 - 2015-07-14 13:37 - 00028222 _____ C:\Users\SRE Lab\Documents\The Stealthy Sniper.wlmp
2015-08-28 10:38 - 2014-09-12 10:03 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-08-28 10:38 - 2014-09-12 10:03 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-08-27 15:47 - 2014-09-16 20:50 - 00000000 ____D C:\Python32
2015-08-26 18:37 - 2014-09-11 13:39 - 134753440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-08-21 10:41 - 2015-04-25 08:54 - 00043520 _____ C:\Windows\SysWOW64\CmdLineExt03.dll
 
==================== Files in the root of some directories =======
 
2014-09-14 15:04 - 2014-09-14 15:04 - 0000044 _____ () C:\Users\SRE Lab\AppData\Roaming\WB.CFG
 
Some files in TEMP:
====================
C:\Users\SRE Lab\AppData\Local\Temp\0261241410748801mcinst.exe
C:\Users\SRE Lab\AppData\Local\Temp\0261371410748805mcinst.exe
C:\Users\SRE Lab\AppData\Local\Temp\0261641410748813mcinst.exe
C:\Users\SRE Lab\AppData\Local\Temp\0262551410748841mcinst.exe
C:\Users\SRE Lab\AppData\Local\Temp\15782uninstall.exe
C:\Users\SRE Lab\AppData\Local\Temp\25638uninstall.exe
C:\Users\SRE Lab\AppData\Local\Temp\26611uninstall.exe
C:\Users\SRE Lab\AppData\Local\Temp\48456uninstall.exe
C:\Users\SRE Lab\AppData\Local\Temp\58650uninstall.exe
C:\Users\SRE Lab\AppData\Local\Temp\80463uninstall.exe
C:\Users\SRE Lab\AppData\Local\Temp\85419uninstall.exe
C:\Users\SRE Lab\AppData\Local\Temp\9125uninstall.exe
C:\Users\SRE Lab\AppData\Local\Temp\EBU10C7.EXE
C:\Users\SRE Lab\AppData\Local\Temp\EBU1357.DLL
C:\Users\SRE Lab\AppData\Local\Temp\EBU13C4.EXE
C:\Users\SRE Lab\AppData\Local\Temp\EBU15A7.DLL
C:\Users\SRE Lab\AppData\Local\Temp\EBU18E3.DLL
C:\Users\SRE Lab\AppData\Local\Temp\EBU3133.EXE
C:\Users\SRE Lab\AppData\Local\Temp\EBU3410.DLL
C:\Users\SRE Lab\AppData\Local\Temp\EBU4272.EXE
C:\Users\SRE Lab\AppData\Local\Temp\EBU4530.DLL
C:\Users\SRE Lab\AppData\Local\Temp\EBU5594.EXE
C:\Users\SRE Lab\AppData\Local\Temp\EBU57D6.DLL
C:\Users\SRE Lab\AppData\Local\Temp\EBU5CB5.EXE
C:\Users\SRE Lab\AppData\Local\Temp\EBU61F3.DLL
C:\Users\SRE Lab\AppData\Local\Temp\EBU9294.EXE
C:\Users\SRE Lab\AppData\Local\Temp\EBU937D.EXE
C:\Users\SRE Lab\AppData\Local\Temp\EBU9551.DLL
C:\Users\SRE Lab\AppData\Local\Temp\EBU9A13.DLL
C:\Users\SRE Lab\AppData\Local\Temp\EBU9BE9.EXE
C:\Users\SRE Lab\AppData\Local\Temp\EBU9FFE.DLL
C:\Users\SRE Lab\AppData\Local\Temp\EBUB7B0.EXE
C:\Users\SRE Lab\AppData\Local\Temp\EBUBAEB.EXE
C:\Users\SRE Lab\AppData\Local\Temp\EBUBCDF.DLL
C:\Users\SRE Lab\AppData\Local\Temp\EBUDAE9.DLL
C:\Users\SRE Lab\AppData\Local\Temp\EBUF80.EXE
C:\Users\SRE Lab\AppData\Local\Temp\SettingsManagerSetup.exe
C:\Users\SRE Lab\AppData\Local\Temp\SIntf16.dll
C:\Users\SRE Lab\AppData\Local\Temp\SIntf32.dll
C:\Users\SRE Lab\AppData\Local\Temp\SIntfNT.dll
C:\Users\SRE Lab\AppData\Local\Temp\Sqlite3.dll
C:\Users\SRE Lab\AppData\Local\Temp\tu17p84.exe
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-09-01 08:40
 
==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:15-09-2015
Ran by [removed] (2015-09-18 11:16:49)
Running from C:\Users\[removed]\Desktop
Windows 7 Professional Service Pack 1 (X64) (2013-10-24 17:26:14)
Boot Mode: Safe Mode (with Networking)
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-2887876563-769068690-2455426777-500 - Administrator - Disabled)
Guest (S-1-5-21-2887876563-769068690-2455426777-501 - Limited - Disabled)
SRE Lab (S-1-5-21-2887876563-769068690-2455426777-1001 - Administrator - Enabled) => C:\Users\SRE Lab
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: McAfee Anti-Virus and Anti-Spyware (Disabled - Up to date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee Anti-Virus and Anti-Spyware (Disabled - Up to date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
FW: McAfee Firewall (Disabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Flash Player 11 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 11.2.202.228 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.1.5.155 - Adobe Systems, Inc.)
Alcor Micro Smart Card Reader Driver (HKLM-x32\…\SZCCID) (Version: 1.7.35.0 - Alcor Micro Corp.)
Alcor Micro Smart Card Reader Driver (x32 Version: 1.7.35.0 - Alcor Micro Corp.) Hidden
Apple Application Support (32-bit) (HKLM-x32\…\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{B255D495-4734-4E9B-B4F5-96702FD4A7B9}) (Version: 3.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}) (Version: 8.2.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom 802.11 Wireless LAN Adapter (HKLM\…\Broadcom 802.11 Wireless LAN Adapter) (Version:  - Broadcom Corporation)
Broadcom Bluetooth Software (HKLM\…\{A1439D4F-FD46-47F2-A1D3-FEE097C29A09}) (Version: 6.5.1.3700 - Broadcom Corporation)
Broadcom Wireless Utility (HKLM\…\Broadcom Wireless Utility) (Version:  - Broadcom Corporation)
CyberLink PowerDVD 12 (HKLM-x32\…\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.2.3115 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 4.2.1.4224 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Energy Star (HKLM-x32\…\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 45.0.2454.85 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.13 - Google Inc.) Hidden
Hewlett-Packard ACLM.NET v1.2.2.1 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP 3D DriveGuard (HKLM-x32\…\{07F6DC37-0857-4B68-A675-4E35989E85E3}) (Version: 6.0.15.1 - Hewlett-Packard Company)
HP Client Security Manager (HKLM\…\HPProtectTools) (Version: 8.2.0.1663 - Hewlett-Packard Company)
HP Connection Manager (HKLM-x32\…\{7ED7BF91-D145-480A-B206-6891576F6935}) (Version: 4.6.12.1 - Hewlett-Packard Company)
HP Device Access Manager (HKLM\…\{9F7FF800-8C11-4741-8D20-92E43CA02FD6}) (Version: 8.2.0.10 - Hewlett-Packard Company)
HP Documentation (HKLM-x32\…\{2032D55B-645D-4A90-98B0-F5C9B20B9537}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Drive Encryption (HKLM\…\HPDriveEncryption) (Version: 8.6.1.160 - Hewlett-Packard Company)
HP ESU for Microsoft Windows 7 (HKLM-x32\…\{240B2BF7-E7E6-425C-A2A4-A3149189BF7F}) (Version: 2.3.1 - Hewlett-Packard Company)
HP File Sanitizer (HKLM-x32\…\{547607B0-3294-4ECA-8F5E-921404676CBB}) (Version: 8.4.11.1 - Hewlett-Packard Company)
HP HD Webcam Driver (HKLM-x32\…\Sunplus SPUVCb) (Version: 3.4.8.28 - SunplusIT)
HP Hotkey Support (HKLM-x32\…\{C807BEFB-0F17-41AC-B307-D7B5E1553040}) (Version: 5.0.20.1 - Hewlett-Packard Company)
HP PageLift (HKLM-x32\…\{708ABF62-5D7A-4550-823A-1F9EFA63645A}) (Version: 1.0.11.1 - Hewlett-Packard Company)
HP Setup (HKLM-x32\…\{438363A8-F486-4C37-834C-4955773CB3D3}) (Version: 9.1.15453.4066 - Hewlett-Packard Company)
HP SoftPaq Download Manager (HKLM-x32\…\{5C2D96B7-0468-4450-8BD9-63AB796D72CF}) (Version: 3.4.11.0 - Hewlett-Packard Company)
HP Software Setup (HKLM-x32\…\{10CCDB7D-D5E9-45BF-8E7A-004398AE04A0}) (Version: 8.7.2.1 - Hewlett-Packard Company)
HP Support Assistant (HKLM-x32\…\{C88F84E5-AE23-44BD-922C-2ABEACACAF7A}) (Version: 7.2.23.56 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\…\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 13.00.0000 - Hewlett-Packard)
HP System Default Settings (HKLM-x32\…\{3A61A282-4F08-4D43-920C-DC30ECE528E8}) (Version: 2.6.1 - Hewlett-Packard Company)
HP Theft Recovery (HKLM-x32\…\InstallShield_{BAC712C6-4061-4C9F-AB58-A5C53E76704A}) (Version: 8.2.0.9 - Hewlett-Packard Company)
HP Trust Circles (HKLM-x32\…\HP Trust Circles) (Version: 8.2.15.16418 - CryptoMill Technologies)
IDT Audio (HKLM-x32\…\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6486.0 - IDT)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.12.1688 - Intel Corporation)
Intel(R) Network Connections Drivers (HKLM\…\PROSet) (Version: 18.5 - Intel)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.18.10.3324 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.7.3.1001 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.66956 - Intel Corporation)
Intel(R) Smart Connect Technology (HKLM\…\{5EC1901C-D946-424C-9E77-4F58F64C987B}) (Version: 4.2.40.2384 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\…\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation)
iTunes (HKLM\…\{6CF1A7E2-8001-4870-9F18-3C6CDD6FE9E3}) (Version: 12.2.1.16 - Apple Inc.)
LEGO Racers (HKLM-x32\…\LEGO Racers) (Version:  - )
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
McAfee SecurityCenter (HKLM-x32\…\MSC) (Version: 14.0.1029 - McAfee, Inc.)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM-x32\…\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Zoo Tycoon (HKLM-x32\…\Zoo Tycoon 1.0) (Version:  - )
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
opensource (x32 Version: 1.0.14960.3876 - Your Company Name) Hidden
Outils de vérification linguistique 2013 de Microsoft Office - Français (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Pac-Man Adventures in Time (HKLM-x32\…\{D2023740-9AAC-11D4-B54D-006008571948}) (Version:  - )
PDF Complete Corporate Edition (HKLM-x32\…\PDF Complete) (Version: 4.1.50 - PDF Complete, Inc)
Pivot Animator version 4.1.10 (HKLM-x32\…\Pivot Animator_is1) (Version: 4.1.10 - Motus Software Ltd)
Pivot StickFigure Animator Packages (HKU\S-1-5-21-2887876563-769068690-2455426777-1001\…\Pivot StickFigure Animator Packages) (Version:  - ) <==== ATTENTION
Pivot Stickfigure Animator version 2.2.7 (HKLM-x32\…\Pivot Stickfigure Animator_is1) (Version: 2.2.7 - )
Python 3.2.1 (64-bit) (HKLM\…\{34b2530c-6349-4292-9dc3-60bda4aed93d}) (Version: 3.2.1150 - Python Software Foundation)
Python 3.4 pygame-1.9.2a0 (HKLM-x32\…\{F6025B65-59B9-476B-8CC5-37F95020EBF5}) (Version: 1.9.2 - Pete Shinners, Rene Dudfield, Marcus von Appen, Bob Pendleton, others…)
Python 3.4.2 (HKLM-x32\…\{2583CDBA-8A53-4622-BB67-1D163714C1B4}) (Version: 3.4.16349 - Python Software Foundation)
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 1.1.9200.22 - Realtek Semiconductor Corp.)
Search Protect (HKLM-x32\…\SearchProtect) (Version: 2.17.18.1 - Client Connect LTD) <==== ATTENTION
Skype™ 7.0 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 17.0.8.3 - Synaptics Incorporated)
Update for Skype for Business 2015 (KB2889853) 32-Bit Edition (HKLM-x32\…\{90150000-012B-0409-0000-0000000FF1CE}_Office15.PROPLUSR_{BF1B3F01-93F3-4B83-93DB-132EB1AED259}) (Version:  - Microsoft)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Restore Points =========================
 
26-08-2015 08:03:25 Windows Update
29-08-2015 11:33:25 Windows Update
02-09-2015 09:19:21 Windows Update
06-09-2015 08:38:43 Windows Update
09-09-2015 14:44:41 Windows Update
09-09-2015 22:52:47 Installed Blackboard Collaborate Launcher
09-09-2015 23:39:05 Installed Blackboard Collaborate Launcher
13-09-2015 19:15:54 Removed Blackboard Collaborate Launcher
14-09-2015 06:10:32 Windows Update
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 19:34 - 2009-06-10 14:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {1923DDFD-FCB3-42DC-8980-A6F59EB79488} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-06-07] (Hewlett-Packard Company)
Task: {1A1FEDE0-4117-4E1F-8004-3D9C3E65B3E9} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {1A998E26-F979-45A5-8E57-5558B0B2D300} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-21] (Microsoft Corporation)
Task: {2933EAFF-1F3D-4C5C-BC33-709DB757B697} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2012-11-29] (Hewlett-Packard Company)
Task: {3E6A9A59-D210-43EB-8B6D-F5333E8A42DC} - System32\Tasks\YTDownloader => C:\Program Files (x86)\YTDownloader\YTDownloader.exe <==== ATTENTION
Task: {44E0A612-04CC-4954-9CB0-91245B0639C5} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-21] (Microsoft Corporation)
Task: {5650C1CA-0F2F-42EA-B8AB-1DB11FEB1FB2} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {5BCAD4CE-47DB-435C-BBA6-151FC63E4AE1} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {5C9C2738-A906-4DF5-89B5-042122909643} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-06-07] (Hewlett-Packard Company)
Task: {72AE8555-A22B-4471-A7D8-5531AB07C596} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-08] (Adobe Systems Incorporated)
Task: {B51AF5A1-EA92-42ED-9B4C-3C07B6BD5318} - System32\Tasks\Registration => C:\Program Files (x86)\Hewlett-Packard\HP Setup\Dependencies\RemEngine.exe [2012-03-21] ()
Task: {C9652D03-85B3-40BC-BED3-B8CA697379BF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {CB646EBD-FB21-4E77-9001-E20DD21C43EC} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe [2015-06-01] (McAfee, Inc.)
Task: {DC72B453-F6C7-4689-89AB-46B575976D5E} - \SMupdate1 -> No File <==== ATTENTION
Task: {F106215B-0764-447F-A203-3485B02E9BD4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {FFCDCDBA-AEA7-4FDE-89A2-E82287C79739} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-03-18 14:08 - 2015-03-18 14:08 - 08898720 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2013-08-07 14:01 - 2013-08-07 14:01 - 02654936 _____ () C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\ShredContextMenu.dll
2015-03-18 14:08 - 2015-03-18 14:08 - 08898720 _____ () C:\Program Files (x86)\Microsoft Office\Office15\1033\GrooveIntlResource.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\SRE Lab\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.150.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{7417BCF3-AB07-4BC9-B3D9-2F3BEB4116AB}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{60FA57F2-317C-42B7-98DD-C8848CF3E4CD}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{166EB59E-6BD1-434A-8088-CE5A661A1837}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{67363868-08C2-4C6C-8E77-B10D2BE09EA1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{0DB0608F-F1A5-4AE2-9066-E7782E70BB22}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{5CF1684F-A688-4FD5-BEB1-175B0A6E8BC0}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe
FirewallRules: [{6D360A95-571D-4859-80A1-583E8A24A201}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe
FirewallRules: [{E4E1C1E9-09C0-4042-852B-465C7961E6C0}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
FirewallRules: [{E04F7CCA-D0C4-4BBF-8965-2637D6D09702}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe
FirewallRules: [{634BCD9C-CB37-4E91-A6C3-A38AC4979681}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{A979F43E-7F43-4083-B3DD-2432455D9330}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [{4D18D2AB-3EE8-450F-BCC5-2820E15BFAFD}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{521A06B7-981B-443C-8C39-0F741FC0D681}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{3B76E00C-0A04-4D5F-852D-A1DAD86317D8}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{88E6FBAD-57AC-4B4D-BD27-214BD467EFBC}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{C6603EB4-C006-4B53-ABAD-950CFDFE469D}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{13658905-AA76-430D-B989-F653951418BF}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [TCP Query User{0D745C17-17E2-4214-8AA2-2EE93AE8BAB4}C:\users\sre lab\desktop\dawn of war\w40k.exe] => (Block) C:\users\sre lab\desktop\dawn of war\w40k.exe
FirewallRules: [UDP Query User{68A0CBAA-604D-46C2-96AF-5887CDDC102C}C:\users\sre lab\desktop\dawn of war\w40k.exe] => (Block) C:\users\sre lab\desktop\dawn of war\w40k.exe
FirewallRules: [{B759129C-3E98-45A1-A327-C7F7E60140FC}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{8B642EBB-B46C-4468-B8E8-AAE3918FFE00}] => (Allow) LPort=2869
FirewallRules: [{3988C02D-30AD-4A81-A82F-BF8156C20FF5}] => (Allow) LPort=1900
FirewallRules: [{41E5BFF8-A718-4B53-B0A6-E815B36CE12C}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{C7A436FD-E582-4ECA-A956-A400A1951981}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{CB6EA577-B071-41FB-B6A2-A9A317E8E25B}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{673FB490-1C18-4932-972C-1E9F76E6DA8B}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{0E2FE106-70A5-482C-976B-48372658F80D}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{731B1686-B76E-49DF-ADAE-DD4C79FE0B57}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Faulty Device Manager Devices =============
 
Name: Microsoft Teredo Tunneling Adapter
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
Name: Security Processor Loader Driver
Description: Security Processor Loader Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: spldr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (09/18/2015 10:19:34 AM) (Source: AVLogEvent) (EventID: 5010) (User: NT AUTHORITY)
Description: McShield failed to start because it is not trusted.
Error Code:a7f40905
 
Error: (09/18/2015 10:19:34 AM) (Source: AVLogEvent) (EventID: 5007) (User: NT AUTHORITY)
Description: Failed to load a dependant module.
Error Code:a7f42003
 
Error: (09/14/2015 07:26:28 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 37222
 
Error: (09/14/2015 07:26:28 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 37222
 
Error: (09/14/2015 07:26:28 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (09/14/2015 07:26:27 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 36223
 
Error: (09/14/2015 07:26:27 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 36223
 
Error: (09/14/2015 07:26:27 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (09/14/2015 07:26:26 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 35209
 
Error: (09/14/2015 07:26:26 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 35209
 
 
System errors:
=============
Error: (09/18/2015 11:15:16 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/18/2015 11:15:16 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/18/2015 11:15:16 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/18/2015 11:15:16 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/18/2015 11:15:16 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/18/2015 11:15:16 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/18/2015 11:15:16 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/18/2015 11:15:16 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/18/2015 11:15:16 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/18/2015 11:15:16 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i5-4200U CPU @ 1.60GHz
Percentage of memory in use: 15%
Total physical RAM: 7833.11 MB
Available physical RAM: 6610.06 MB
Total Virtual: 15664.42 MB
Available Virtual: 14539.52 MB
 
==================== Drives ================================
 
Drive c: (Windows) (Fixed) (Total:451.31 GB) (Free:365.83 GB) NTFS
Drive d: (HP_RECOVERY) (Fixed) (Total:11.45 GB) (Free:1.27 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive e: (HP_TOOLS) (Fixed) (Total:1.99 GB) (Free:1.98 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 0FE3875A)
Partition 1: (Active) - (Size=1 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=451.3 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=11.4 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=2 GB) - (Type=0B)
 
==================== End of Addition.txt ============================
 

 

:welcome:

 

You have a bit going on, lets run this quick fix first and then download and run the tools that I am posting, I need to see the logs from each one. 

 

Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist, Save it to your desktop where you have FRST/FRST64 or the fix wont work, . Then open up FRST/FRST64 and click on FIX (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
 
Start
CloseProcesses:
CreateRestorePoint: 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\…\Run: [] => [X]
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\…\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
C:\Program Files (x86)\YTDownloader
AppInit_DLLs: C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => No File
AppInit_DLLs-x32: C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll => No File
C:\Program Files (x86)\SearchProtect
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] =
Task: {3E6A9A59-D210-43EB-8B6D-F5333E8A42DC} - System32\Tasks\YTDownloader => C:\Program Files (x86)\YTDownloader\YTDownloader.exe <==== ATTENTION
Task: {DC72B453-F6C7-4689-89AB-46B575976D5E} - \SMupdate1 -> No File <==== ATTENTION
Hosts:
CMD: ipconfig /flushdns
EmptyTemp:
End
 
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
 
 
=================================================================
 
 
 

 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner TO YOUR DESKTOP
Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
 
Do not click on any links in the top Advertisment.
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
  •  
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
 
 
 
===============================================================================
 
 
 
[external image: thisisujrt.gif] Please download Junkware Removal Tool TO YOUR DESKTOP
  •  
  • Download the one from Bleeping Computer
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
 
 
 
 
===============================================================================
 
Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
 
  •  
  • Windows XP : Double click on the icon to run it.
  • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
 
 
[external image: 0841859c-1a35-4dbd-b41a-e720629e3e22_zps]
 
  •  
  • On the Dashboard click on Update Now
  • Go to the Setting Tab
  • Under Setting go to Detection and Protection
  • Under PUP and PUM make sure both are set to show Treat Detections as Malware
  • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
  • Then on the Dashboard click on Scan
  • Make sure to select THREAT SCAN
  • Then click on Scan
  • When the scan is finished on the bottom right click on SAVE RESULTS then select Copy to Clipboard
  • Please paste the log back into this thread for review
  • Exit Malwarebytes
 
 
Fix result of Farbar Recovery Scan Tool (x64) Version:15-09-2015
Ran by [removed] (2015-09-21 21:56:00) Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Safe Mode (with Networking)
==============================================
 
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint: 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\…\Run: [] => [X]
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\…\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
C:\Program Files (x86)\YTDownloader
AppInit_DLLs: C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => No File
AppInit_DLLs-x32: C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll => No File
C:\Program Files (x86)\SearchProtect
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] =
Task: {3E6A9A59-D210-43EB-8B6D-F5333E8A42DC} - System32\Tasks\YTDownloader => C:\Program Files (x86)\YTDownloader\YTDownloader.exe <==== ATTENTION
Task: {DC72B453-F6C7-4689-89AB-46B575976D5E} - \SMupdate1 -> No File <==== ATTENTION
Hosts:
CMD: ipconfig /flushdns
EmptyTemp:
End
*****************
 
Processes closed successfully.
Error: Restore point can only be created in normal mode.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\YTDownloader => value removed successfully
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\Software\Microsoft\Windows\CurrentVersion\Run\\YTDownloader => value removed successfully
"C:\Program Files (x86)\YTDownloader" => File/Folder not found.
"C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll" => Value data not found.
"C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll" => Value data not found.
"C:\Program Files (x86)\SearchProtect" => File/Folder not found.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3E6A9A59-D210-43EB-8B6D-F5333E8A42DC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3E6A9A59-D210-43EB-8B6D-F5333E8A42DC}" => key removed successfully
C:\Windows\System32\Tasks\YTDownloader => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YTDownloader" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{DC72B453-F6C7-4689-89AB-46B575976D5E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DC72B453-F6C7-4689-89AB-46B575976D5E}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SMupdate1 => key not found. 
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
 
=========  ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
EmptyTemp: => 1.5 GB temporary data Removed.
 
 
The system needed a reboot.. 
 
==== End of Fixlog 21:56:31 ====
 
# AdwCleaner v5.008 - Logfile created 21/09/2015 at 22:05:41
# Updated 18/09/2015 by Xplode
# Database : 2015-09-20.1 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x64)
# Username : SRE Lab - SRELAB-HP
# Running from : C:\Users\SRE Lab\Downloads\AdwCleaner.exe
# Option : Scan
# Support : http://toolslib.net/forum
 
***** [ Services ] *****
 
 
***** [ Folders ] *****
 
Folder Found : C:\Program Files (x86)\globalUpdate
Folder Found : C:\ProgramData\Browser
Folder Found : C:\ProgramData\{4A268D42-77A5-4E91-AE73-470ED3BD9CA8}
Folder Found : C:\Users\SRE Lab\AppData\Local\globalUpdate
 
***** [ Files ] *****
 
File Found : C:\Program Files\Common Files\System\SysMenu.dll
File Found : C:\Program Files\Common Files\System\SysMenu64.dll
 
***** [ Shortcuts ] *****
 
 
***** [ Scheduled tasks ] *****
 
 
***** [ Registry ] *****
 
Key Found : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Key Found : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Found : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Found : HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\SysMenuExt
Key Found : HKLM\SOFTWARE\Classes\AppID\SysMenu.DLL
Key Found : HKLM\SYSTEM\CurrentControlSet\Control\Class\{0014298C-A9BA-440D-AAA8-AD12C7010EE5}
Key Found : HKLM\SYSTEM\CurrentControlSet\Control\Class\{181A06EA-B82C-47DE-B851-E20FD0E1CC7D}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\smu.exe
Key Found : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Key Found : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Found : HKLM\SOFTWARE\Classes\AppID\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706}
Key Found : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Found : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Found : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Found : HKLM\SOFTWARE\Classes\AppID\{D813D5BB-EBC7-45F9-B8A4-36A305168069}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{61AB12E1-A5FF-11D1-B2E9-444553540000}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{020B1D4B-5738-4C77-9E19-4F173DD9B486}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Found : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Found : HKCU\Software\GlobalUpdate
Key Found : HKCU\Software\Softonic
Key Found : HKCU\Software\StormWatch
Key Found : HKLM\SOFTWARE\GlobalUpdate
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Key Found : [x64] HKCU\Software\GlobalUpdate
Key Found : [x64] HKCU\Software\Softonic
Key Found : [x64] HKCU\Software\StormWatch
Key Found : [x64] HKLM\SOFTWARE\ShopperPro
Key Found : [x64] HKLM\SOFTWARE\YTDownloader
Data Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll
Data Found : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll
 
***** [ Web browsers ] *****
 
[C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
[C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com
[C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : bbjciahceamgodcoidkjpchnokgfpphh
 
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [4495 bytes] ##########
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.2 (09.14.2015:1)
OS: Windows 7 Professional x64
Ran by [removed] on Mon 09/21/2015 at 22:16:25.89
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Tasks
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
Successfully deleted: [Folder] C:\Users\SRE Lab\Appdata\Local\crashrpt
Successfully deleted: [Folder] C:\Windows\SysWOW64\ai_recyclebin
 
 
 
~~~ Chrome
 
 
[C:\Users\SRE Lab\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
 
[C:\Users\SRE Lab\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
 
[C:\Users\SRE Lab\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
 
[C:\Users\SRE Lab\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 09/21/2015 at 22:18:56.73
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 9/21/2015
Scan Time: 10:24 PM
Logfile: mbamlog.txt
Administrator: Yes
 
Version: 2.1.8.1057
Malware Database: v2015.09.22.02
Rootkit Database: v2015.09.18.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: SRE Lab
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 353544
Time Elapsed: 10 min, 29 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 0
(No malicious items detected)
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)
 

Good Morning Eric

 

1. Your AdwCleaner log is from the scan, did you run the Clean process to remove all that garbage, if not run AdwCleaner again and this time after the scan click on Clean

 

2. Why are you running the scans in Safemode, can you not boot up normally ?

 

3. Go ahead and open up FRST, be sure to put a checkmark in Additions, run a new scan and post both the new FRST and Additions logs.

 

4. Is your system behaving any better now ?

I did run Cleaning in AdwCleaner. Log below. You had asked for the other log.

 

Booting in Safe Mode because the system remains available for use longer than when booted normally.

 

FRST logs below.

 

System still not running well when booted normally.

 

 

# AdwCleaner v5.008 - Logfile created 21/09/2015 at 22:09:23
# Updated 18/09/2015 by Xplode
# Database : 2015-09-20.1 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x64)
# Username : SRE Lab - SRELAB-HP
# Running from : C:\Users\SRE Lab\Downloads\AdwCleaner.exe
# Option : Cleaning
# Support : http://toolslib.net/forum
 
***** [ Services ] *****
 
 
***** [ Folders ] *****
 
[-] Folder Deleted : C:\Program Files (x86)\globalUpdate
[-] Folder Deleted : C:\ProgramData\Browser
[-] Folder Deleted : C:\ProgramData\{4A268D42-77A5-4E91-AE73-470ED3BD9CA8}
[-] Folder Deleted : C:\Users\SRE Lab\AppData\Local\globalUpdate
 
***** [ Files ] *****
 
[-] File Deleted : C:\Program Files\Common Files\System\SysMenu.dll
[-] File Deleted : C:\Program Files\Common Files\System\SysMenu64.dll
 
***** [ Shortcuts ] *****
 
 
***** [ Scheduled tasks ] *****
 
 
***** [ Registry ] *****
 
[-] Key Deleted : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
[-] Key Deleted : HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\SysMenuExt
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\SysMenu.DLL
[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\Class\{0014298C-A9BA-440D-AAA8-AD12C7010EE5}
[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\Class\{181A06EA-B82C-47DE-B851-E20FD0E1CC7D}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\smu.exe
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{960DF771-CFCB-4E53-A5B5-6EF2BBE6E706}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D813D5BB-EBC7-45F9-B8A4-36A305168069}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{61AB12E1-A5FF-11D1-B2E9-444553540000}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{020B1D4B-5738-4C77-9E19-4F173DD9B486}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
[-] Key Deleted : HKCU\Software\GlobalUpdate
[-] Key Deleted : HKCU\Software\Softonic
[-] Key Deleted : HKCU\Software\StormWatch
[-] Key Deleted : HKLM\SOFTWARE\GlobalUpdate
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
[!] Key Not Deleted : [x64] HKCU\Software\GlobalUpdate
[!] Key Not Deleted : [x64] HKCU\Software\Softonic
[!] Key Not Deleted : [x64] HKCU\Software\StormWatch
[-] Key Deleted : [x64] HKLM\SOFTWARE\ShopperPro
[-] Key Deleted : [x64] HKLM\SOFTWARE\YTDownloader
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs]
[-] Data Restored : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs]
 
***** [ Web browsers ] *****
 
[-] [C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
[-] [C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com
[-] [C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : bbjciahceamgodcoidkjpchnokgfpphh
 
*************************
 
:: Winsock settings cleared
 
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [4743 bytes] ##########
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:15-09-2015
Ran by [removed] (administrator) on SRELAB-HP (22-09-2015 20:39:59)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286056 2013-07-30] (Intel Corporation)
HKLM\…\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1703424 2013-07-04] (IDT, Inc.)
HKLM\…\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.exe [7032320 2013-09-30] (Broadcom Corporation)
HKLM\…\Run: [CryptoMill Refresh] => C:\Program Files\Hewlett-Packard\HP Trust Circles\ceflauncher -m refresh
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2774256 2013-08-19] (Synaptics Incorporated)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.)
HKLM-x32\…\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [683656 2013-07-18] (PDF Complete Inc)
HKLM-x32\…\Run: [HPConnectionManager] => c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [185144 2013-08-15] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\…\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [337184 2013-07-31] (Hewlett-Packard Company)
HKLM-x32\…\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation)
HKLM-x32\…\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [77088 2013-07-24] (Hewlett-Packard Company)
HKLM-x32\…\Run: [YouCam Mirage] => c:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488 2013-06-24] (CyberLink)
HKLM-x32\…\Run: [YouCam Tray] => c:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe [167488 2013-06-24] (CyberLink Corp.)
HKLM-x32\…\Run: [HP File Sanitizer] => C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\Coreshredder.exe [2213592 2013-08-07] (Hewlett-Packard)
HKLM-x32\…\Run: [mcpltui_exe] => C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe [719272 2015-04-02] (McAfee, Inc.)
HKLM\…\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe,
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\…\Policies\Explorer: [NoFolderOptions] 0
HKLM\…\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\…\RunOnce: [Application Restart #0] => C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CORESHREDDER.exe [2213592 2013-08-07] (Hewlett-Packard)
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\…\RunOnce: [Application Restart #1] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944 2015-08-27] (Google Inc.)
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\…\RunOnce: [Report] => C:\AdwCleaner\AdwCleaner[C1].txt [4862 2015-09-21] ()
AppInit_DLLs: C:\Program Files => C:\Program Files [0 2015-07-14] ()
AppInit_DLLs-x32: C:\Program Files => C:\Program Files [0 2015-07-14] ()
Lsa: [Notification Packages] DPPassFilter scecli c:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
ShellIconOverlayIdentifiers: [+1TBIcon] -> {B9C55E85-DED6-4911-82F3-83CF1CAB2898} => C:\Program Files\Hewlett-Packard\HP Trust Circles\tbicon.dll [2013-08-22] (CryptoMill Technologies Ltd.)
ShellIconOverlayIdentifiers-x32: [+1TBIcon] -> {B9C55E85-DED6-4911-82F3-83CF1CAB2898} => C:\Program Files (x86)\Hewlett-Packard\HP Trust Circles\tbicon.dll [2013-08-22] (CryptoMill Technologies Ltd.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2013-09-30]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ISCTSystray.lnk [2013-09-30]
ShortcutTarget: ISCTSystray.lnk -> C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe (Intel Corporation)
Startup: C:\Users\SRE Lab\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PowerReg Scheduler.exe [2014-09-23] ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.150.1
Tcpip\..\Interfaces\{74926853-863F-4080-A8D2-B951833BED4F}: [DhcpNameServer] 192.168.150.1
Tcpip\..\Interfaces\{D98EC19B-EFC7-45D0-AE7E-E35FE2A78D92}: [DhcpNameServer] 192.168.150.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCOM14/1
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCOM14/1
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCOM14/1
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-08-12] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-21] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-07-14] (Microsoft Corporation)
BHO-x32: HP File Sanitizer -> {3134413B-49B4-425C-98A5-893C1F195601} -> C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2013-08-07] (Hewlett-Packard)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-08-12] (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-07-14] (Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2012-07-09] (Hewlett-Packard)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\program files\mcafee\msc\mcsniepl64.dll [2015-04-07] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\program files (x86)\mcafee\msc\mcsniepl.dll [2015-04-07] (McAfee, Inc.)
 
FireFox:
========
FF Plugin: @mcafee.com/MSC,version=10 -> c:\program files\mcafee\msc\npmcsnffpl64.dll [2015-04-07] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1215155.dll [2014-12-02] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-07-25] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-07-25] (Intel Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\program files (x86)\mcafee\msc\npmcsnffpl.dll [2015-04-07] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-03-31] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-28] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Plugin-x32: digitalpersona.com/ChromeDPAgent -> C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\ChromeExt\components\npChromeDPAgent.dll [2013-08-05] (DigitalPersona, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-03-31] (Microsoft Corporation)
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt
FF Extension: DigitalPersona Extension - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt [2013-09-30]
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://google.com/"
CHR Profile: C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-12]
CHR Extension: (Google Docs) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-12]
CHR Extension: (Google Drive) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-12]
CHR Extension: (YouTube) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-12]
CHR Extension: (Google Search) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-12]
CHR Extension: (Google Sheets) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-12]
CHR Extension: (Google Docs Offline) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-02]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13]
CHR Extension: (DigitalPersona Extension) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncffjdbbodifgldkcbhmiiljfcnbgjab [2014-09-12]
CHR Extension: (Chrome Web Store Payments) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-12]
CHR Extension: (Gmail) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-12]
CHR HKLM-x32\…\Chrome\Extension: [ncffjdbbodifgldkcbhmiiljfcnbgjab] - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\ChromeExt\dpchrome.crx [2013-08-05]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
S2 CreoService; C:\Program Files (x86)\Hewlett-Packard\HP Trust Circles\CreoSvc.exe [1366488 2013-08-22] (CryptoMill Technologies Ltd.)
S2 CtAgentService; C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe [7168 2013-08-07] () [File not signed]
S2 DpHost; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [500048 2013-08-05] (DigitalPersona, Inc.)
S3 FLCDLOCK; c:\Windows\SysWOW64\flcdlock.exe [558392 2013-08-06] (Hewlett-Packard Company)
S2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc.)
S2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-06-07] (Hewlett-Packard Company) [File not signed]
S2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe [681760 2013-07-31] (Hewlett-Packard Company)
S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [14696 2013-07-30] (Intel Corporation)
S2 Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
S2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-07-25] (Intel Corporation)
S2 ISCTAgent; c:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [197608 2013-07-22] ()
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-07-25] (Intel Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [753768 2015-04-07] (McAfee, Inc.)
S2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.5.450.0\McCSPServiceHost.exe [207344 2015-04-08] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc.)
S2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [612688 2015-04-09] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc.)
S2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [232656 2015-02-17] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [372144 2015-04-06] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [250672 2015-02-17] (McAfee, Inc.)
S2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1143432 2013-07-18] (PDF Complete Inc)
S2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [337920 2013-07-04] (IDT, Inc.) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
S2 wltrysvc; C:\Program Files\Broadcom\Broadcom 802.11\bcmwltry.exe [5878272 2013-09-30] (Broadcom Corporation) [File not signed]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [165688 2012-09-24] (Broadcom Corporation.)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [68784 2015-02-17] (McAfee, Inc.)
S3 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [65752 2013-06-13] (Hewlett-Packard Company)
R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [488216 2014-02-28] (Intel Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [28008 2013-07-30] (Intel Corporation)
S3 IceKore; C:\Windows\System32\DRIVERS\IceKore.sys [397784 2013-08-19] (CryptoMill Technologies Inc.)
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [21408 2013-07-22] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [21920 2013-07-22] ()
S3 INETMON; C:\Windows\System32\Drivers\INETMON.sys [29088 2013-07-22] ()
R3 ISCT; C:\Windows\system32\drivers\ISCTD64.sys [46568 2013-07-22] ()
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-12-19] (Intel Corporation)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [401736 2015-02-17] (McAfee, Inc.)
S3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [337888 2015-02-17] (McAfee, Inc.)
R0 mfedisk; C:\Windows\System32\DRIVERS\mfedisk.sys [101872 2015-02-17] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [488000 2015-02-17] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [864072 2015-02-17] (McAfee, Inc.)
S3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [482600 2015-01-16] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [100720 2015-01-16] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [340448 2015-02-17] (McAfee, Inc.)
R0 PinFile; C:\Windows\System32\DRIVERS\PinFile.sys [49856 2013-07-16] (WinMagic Inc.)
S3 RTSPER; C:\Windows\System32\DRIVERS\RtsPer.sys [427736 2013-08-09] (Realsil Semiconductor Corporation)
R0 SDDisk2K; C:\Windows\System32\DRIVERS\SDDisk2K.sys [228544 2013-07-16] (WinMagic Inc.)
R0 SDDToki; C:\Windows\System32\DRIVERS\SDDToki.sys [131264 2013-07-16] (WinMagic Inc.)
S3 SmbDrv; C:\Windows\system32\drivers\Smb_driver_AMDASF.sys [30448 2013-08-19] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\system32\drivers\Smb_driver_Intel.sys [34544 2013-08-19] (Synaptics Incorporated)
S3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [1512568 2013-06-25] (Sunplus)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-21 22:20 - 2015-09-21 22:20 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\SRE Lab\Desktop\mbam-setup-2.1.8.1057 (2).exe
2015-09-21 22:20 - 2015-09-21 22:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2015-09-21 22:18 - 2015-09-21 22:18 - 00001221 _____ C:\Users\SRE Lab\Desktop\JRT.txt
2015-09-21 22:15 - 2015-09-21 22:15 - 01798976 _____ (Malwarebytes) C:\Users\SRE Lab\Desktop\JRT.exe
2015-09-21 22:05 - 2015-09-21 22:09 - 00000000 ____D C:\AdwCleaner
2015-09-21 22:03 - 2015-09-21 22:03 - 01662976 _____ C:\Users\SRE Lab\Downloads\AdwCleaner.exe
2015-09-18 11:16 - 2015-09-22 20:40 - 00020680 _____ C:\Users\SRE Lab\Desktop\FRST.txt
2015-09-18 11:16 - 2015-09-18 11:17 - 00029866 _____ C:\Users\SRE Lab\Desktop\Addition.txt
2015-09-18 11:15 - 2015-09-22 20:40 - 00000000 ____D C:\FRST
2015-09-18 11:09 - 2015-09-18 11:14 - 02191360 _____ (Farbar) C:\Users\SRE Lab\Desktop\FRST64.exe
2015-09-18 11:07 - 2015-09-18 11:07 - 00002306 _____ C:\Users\SRE Lab\Desktop\aswMBR.txt
2015-09-18 11:07 - 2015-09-18 11:07 - 00000512 _____ C:\Users\SRE Lab\Desktop\MBR.dat
2015-09-18 10:54 - 2015-09-18 10:55 - 05198336 _____ (AVAST Software) C:\Users\SRE Lab\Desktop\aswMBR.exe
2015-09-13 19:36 - 2015-09-21 22:22 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-09-13 19:35 - 2015-09-21 22:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-09-13 19:35 - 2015-09-21 22:21 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-09-13 19:35 - 2015-09-13 19:35 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-09-13 19:35 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-09-13 19:35 - 2015-06-18 08:41 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-09-13 19:35 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-09-13 19:32 - 2015-09-13 19:34 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\SRE Lab\Downloads\mbam-setup-2.1.8.1057 (1).exe
2015-09-13 19:32 - 2015-09-13 19:33 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\SRE Lab\Downloads\mbam-setup-2.1.8.1057.exe
2015-09-13 18:43 - 2015-09-13 18:43 - 00003280 ____N C:\bootsqm.dat
2015-09-10 08:24 - 2015-09-10 08:24 - 00010731 _____ C:\Users\SRE Lab\Downloads\meeting.collab
2015-09-10 08:24 - 2015-09-10 08:24 - 00010731 _____ C:\Users\SRE Lab\Downloads\meeting (1).collab
2015-09-09 23:48 - 2015-09-09 23:48 - 00008432 _____ C:\Users\SRE Lab\Downloads\work_room (1).collab
2015-09-09 23:45 - 2015-09-09 23:46 - 00000000 ____D C:\Users\SRE Lab\AppData\Roaming\Blackboard
2015-09-09 23:39 - 2015-09-09 23:39 - 00000000 ____D C:\Users\SRE Lab\AppData\Local\Blackboard
2015-09-09 15:19 - 2015-08-17 18:42 - 00393304 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-09-09 15:19 - 2015-08-17 18:14 - 00344168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-09-09 15:19 - 2015-08-14 23:48 - 25190400 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-09-09 15:19 - 2015-08-14 23:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-09-09 15:19 - 2015-08-14 23:33 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-09-09 15:19 - 2015-08-14 23:18 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-09-09 15:19 - 2015-08-14 23:18 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-09-09 15:19 - 2015-08-14 23:17 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-09-09 15:19 - 2015-08-14 23:17 - 00585216 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-09-09 15:19 - 2015-08-14 23:17 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-09-09 15:19 - 2015-08-14 23:17 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-09-09 15:19 - 2015-08-14 23:10 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-09-09 15:19 - 2015-08-14 23:09 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-09-09 15:19 - 2015-08-14 23:06 - 19856896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-09-09 15:19 - 2015-08-14 23:06 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-09-09 15:19 - 2015-08-14 23:04 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-09-09 15:19 - 2015-08-14 23:04 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-09-09 15:19 - 2015-08-14 23:04 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-09-09 15:19 - 2015-08-14 23:04 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-09-09 15:19 - 2015-08-14 23:00 - 05923328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-09-09 15:19 - 2015-08-14 22:57 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-09-09 15:19 - 2015-08-14 22:53 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-09-09 15:19 - 2015-08-14 22:53 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-09-09 15:19 - 2015-08-14 22:46 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-09-09 15:19 - 2015-08-14 22:42 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-09-09 15:19 - 2015-08-14 22:41 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-09-09 15:19 - 2015-08-14 22:40 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-09-09 15:19 - 2015-08-14 22:40 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-09-09 15:19 - 2015-08-14 22:39 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-09-09 15:19 - 2015-08-14 22:39 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-09-09 15:19 - 2015-08-14 22:39 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-09-09 15:19 - 2015-08-14 22:38 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-09-09 15:19 - 2015-08-14 22:35 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-09-09 15:19 - 2015-08-14 22:33 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-09-09 15:19 - 2015-08-14 22:32 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-09-09 15:19 - 2015-08-14 22:30 - 00479232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-09-09 15:19 - 2015-08-14 22:29 - 00665600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-09-09 15:19 - 2015-08-14 22:29 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-09-09 15:19 - 2015-08-14 22:29 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-09-09 15:19 - 2015-08-14 22:24 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-09-09 15:19 - 2015-08-14 22:23 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-09-09 15:19 - 2015-08-14 22:22 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-09-09 15:19 - 2015-08-14 22:22 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-09-09 15:19 - 2015-08-14 22:21 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-09-09 15:19 - 2015-08-14 22:16 - 14451712 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-09-09 15:19 - 2015-08-14 22:16 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-09-09 15:19 - 2015-08-14 22:14 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-09-09 15:19 - 2015-08-14 22:12 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-09-09 15:19 - 2015-08-14 22:11 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-09-09 15:19 - 2015-08-14 22:10 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-09-09 15:19 - 2015-08-14 22:07 - 02427392 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-09-09 15:19 - 2015-08-14 22:04 - 12857344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-09-09 15:19 - 2015-08-14 22:02 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-09-09 15:19 - 2015-08-14 22:01 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-09-09 15:19 - 2015-08-14 22:01 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-09-09 15:19 - 2015-08-14 21:55 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-09-09 15:19 - 2015-08-14 21:43 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-09-09 15:19 - 2015-08-14 21:43 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-09-09 15:19 - 2015-08-14 21:39 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-09-09 15:19 - 2015-08-14 21:37 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-09-09 15:19 - 2015-08-05 10:56 - 01110016 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2015-09-09 15:19 - 2015-07-14 20:17 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-09-09 15:19 - 2015-07-14 19:54 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2015-09-09 15:19 - 2015-07-09 10:58 - 01632256 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-09-09 15:19 - 2015-07-09 10:58 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2015-09-09 15:19 - 2015-07-09 10:42 - 01372160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-09-09 15:19 - 2015-07-09 10:42 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2015-09-09 15:14 - 2015-08-27 11:18 - 02004480 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-09-09 15:14 - 2015-08-27 11:18 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-09-09 15:14 - 2015-08-27 11:13 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2015-09-09 15:14 - 2015-08-27 11:13 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-09-09 15:14 - 2015-08-27 10:58 - 01391104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2015-09-09 15:14 - 2015-08-27 10:58 - 01241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-09-09 15:14 - 2015-08-27 10:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2015-09-09 15:14 - 2015-08-27 10:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2015-09-09 15:14 - 2015-06-25 03:06 - 00115136 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-09-09 15:14 - 2015-06-25 03:01 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-09-09 15:14 - 2015-06-25 03:01 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2015-09-09 15:14 - 2015-06-25 02:44 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-09-09 15:13 - 2015-09-01 20:04 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-09-09 15:13 - 2015-09-01 20:04 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-09-09 15:13 - 2015-09-01 20:04 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-09-09 15:13 - 2015-09-01 20:04 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-09-09 15:13 - 2015-09-01 19:48 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-09-09 15:13 - 2015-09-01 19:48 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-09-09 15:13 - 2015-09-01 19:48 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-09-09 15:13 - 2015-09-01 19:47 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-09-09 15:13 - 2015-09-01 18:51 - 03209216 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-09-09 15:13 - 2015-09-01 18:47 - 00372736 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-09-09 15:13 - 2015-09-01 18:33 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-09-09 15:12 - 2015-08-26 11:07 - 03165696 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-09-09 15:12 - 2015-08-26 11:07 - 02606080 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-09-09 15:12 - 2015-08-26 11:07 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-09-09 15:12 - 2015-08-26 11:07 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-09-09 15:12 - 2015-08-26 11:07 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-09-09 15:12 - 2015-08-26 11:07 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-09-09 15:12 - 2015-08-26 11:07 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-09-09 15:12 - 2015-08-26 11:06 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-09-09 15:12 - 2015-08-26 11:06 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-09-09 15:12 - 2015-08-26 11:06 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-09-09 15:12 - 2015-08-26 11:06 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-09-09 15:12 - 2015-08-26 10:56 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-09-09 15:12 - 2015-08-26 10:56 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-09-09 15:12 - 2015-08-26 10:56 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-09-09 15:12 - 2015-08-26 10:56 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-09-09 15:12 - 2015-08-26 10:55 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-09-06 12:53 - 2015-09-06 12:54 - 25482411 _____ C:\Users\SRE Lab\Desktop\The infiltrator.mp4
2015-09-01 13:50 - 2015-09-01 13:50 - 00002095 _____ C:\Users\Public\Desktop\Zoo Tycoon.lnk
2015-09-01 13:50 - 2015-09-01 13:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
2015-09-01 13:33 - 2015-09-01 13:33 - 00001336 _____ C:\Users\SRE Lab\Desktop\LEGO Racers.lnk
2015-08-31 15:16 - 2015-09-01 12:59 - 00000000 ____D C:\Users\SRE Lab\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-08-31 15:07 - 2015-08-31 15:07 - 00000000 ____D C:\Program Files (x86)\Microsoft Games
2015-08-27 16:15 - 2015-08-27 16:16 - 00271113 _____ C:\Users\SRE Lab\Downloads\pac-man.zip
2015-08-27 13:12 - 2015-08-27 13:13 - 20822282 _____ C:\Users\SRE Lab\Desktop\THe Trashie strongarm.mp4
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-21 22:11 - 2009-07-13 21:51 - 00109998 _____ C:\Windows\setupact.log
2015-09-21 22:10 - 2014-09-12 10:03 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-21 22:10 - 2013-09-30 10:13 - 00000225 _____ C:\Windows\CryptoMill_CreoService.log
2015-09-21 22:10 - 2013-09-08 21:35 - 00000000 ____D C:\ProgramData\PDFC
2015-09-21 22:10 - 2009-07-13 22:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-21 22:09 - 2009-07-13 20:20 - 00000000 ____D C:\Program Files\Common Files\System
2015-09-21 21:59 - 2013-09-08 21:35 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-09-21 21:59 - 2013-09-08 21:35 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-09-21 21:57 - 2013-09-30 10:13 - 00000225 _____ C:\Windows\CryptoMill_CreoService.001
2015-09-21 21:43 - 2014-09-12 10:03 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-21 21:33 - 2009-07-13 22:13 - 00805126 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-21 21:27 - 2009-07-13 21:45 - 00026832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-09-21 21:26 - 2009-07-13 21:45 - 00026832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-09-21 21:19 - 2013-09-30 10:13 - 00000225 _____ C:\Windows\CryptoMill_CreoService.002
2015-09-19 12:18 - 2013-09-30 10:13 - 00000225 _____ C:\Windows\CryptoMill_CreoService.003
2015-09-14 10:52 - 2013-09-30 10:13 - 00000225 _____ C:\Windows\CryptoMill_CreoService.004
2015-09-14 06:53 - 2013-09-30 10:13 - 00000225 _____ C:\Windows\CryptoMill_CreoService.005
2015-09-14 06:53 - 2009-07-13 21:45 - 00433064 _____ C:\Windows\system32\FNTCACHE.DAT
2015-09-14 06:51 - 2013-10-24 10:28 - 01312624 _____ C:\Windows\WindowsUpdate.log
2015-09-14 06:51 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-09-14 06:35 - 2014-09-12 11:24 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-09-14 06:35 - 2014-09-12 11:20 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-09-14 06:33 - 2014-09-11 13:39 - 00000000 ____D C:\Windows\system32\MRT
2015-09-14 06:25 - 2009-07-13 19:34 - 00000580 _____ C:\Windows\win.ini
2015-09-13 20:25 - 2010-11-20 20:47 - 00317134 _____ C:\Windows\PFRO.log
2015-09-13 19:17 - 2015-07-25 10:07 - 00000000 ____D C:\Users\SRE Lab\AppData\Local\Unity
2015-09-13 19:16 - 2014-09-12 06:29 - 00000000 ____D C:\Windows\system32\appmgmt
2015-09-13 18:39 - 2015-02-28 21:43 - 00000000 ____D C:\Users\SRE Lab\AppData\Local\Intel_Corporation
2015-09-13 15:08 - 2013-10-24 10:27 - 00003938 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{DD9B90AE-3AD8-4A15-A8BB-9A1EB32D171F}
2015-09-13 14:54 - 2014-09-14 15:54 - 00000000 ____D C:\Users\SRE Lab\AppData\Local\CrashDumps
2015-09-11 11:44 - 2014-10-13 20:30 - 00000000 ____D C:\Users\SRE Lab\Documents\Outlook Files
2015-09-10 16:46 - 2014-09-12 10:03 - 00000000 ____D C:\Users\SRE Lab\AppData\Local\Google
2015-09-06 13:57 - 2015-05-16 17:11 - 00000000 ____D C:\Users\SRE Lab\Desktop\Dawn Of War
2015-09-05 18:30 - 2015-07-14 13:37 - 00028222 _____ C:\Users\SRE Lab\Documents\The Stealthy Sniper.wlmp
2015-08-28 10:38 - 2014-09-12 10:03 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-08-28 10:38 - 2014-09-12 10:03 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-08-27 15:47 - 2014-09-16 20:50 - 00000000 ____D C:\Python32
2015-08-26 18:37 - 2014-09-11 13:39 - 134753440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
 
==================== Files in the root of some directories =======
 
2014-09-14 15:04 - 2014-09-14 15:04 - 0000044 _____ () C:\Users\SRE Lab\AppData\Roaming\WB.CFG
 
Some files in TEMP:
====================
C:\Users\SRE Lab\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-09-01 08:40
 
==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:15-09-2015
Ran by [removed] (2015-09-22 20:40:26)
Running from C:\Users\[removed]\Desktop
Windows 7 Professional Service Pack 1 (X64) (2013-10-24 17:26:14)
Boot Mode: Safe Mode (with Networking)
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-2887876563-769068690-2455426777-500 - Administrator - Disabled)
Guest (S-1-5-21-2887876563-769068690-2455426777-501 - Limited - Disabled)
SRE Lab (S-1-5-21-2887876563-769068690-2455426777-1001 - Administrator - Enabled) => C:\Users\SRE Lab
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: McAfee Anti-Virus and Anti-Spyware (Disabled - Up to date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee Anti-Virus and Anti-Spyware (Disabled - Up to date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
FW: McAfee Firewall (Disabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Flash Player 11 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 11.2.202.228 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.1.5.155 - Adobe Systems, Inc.)
Alcor Micro Smart Card Reader Driver (HKLM-x32\…\SZCCID) (Version: 1.7.35.0 - Alcor Micro Corp.)
Alcor Micro Smart Card Reader Driver (x32 Version: 1.7.35.0 - Alcor Micro Corp.) Hidden
Apple Application Support (32-bit) (HKLM-x32\…\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{B255D495-4734-4E9B-B4F5-96702FD4A7B9}) (Version: 3.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}) (Version: 8.2.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom 802.11 Wireless LAN Adapter (HKLM\…\Broadcom 802.11 Wireless LAN Adapter) (Version:  - Broadcom Corporation)
Broadcom Bluetooth Software (HKLM\…\{A1439D4F-FD46-47F2-A1D3-FEE097C29A09}) (Version: 6.5.1.3700 - Broadcom Corporation)
Broadcom Wireless Utility (HKLM\…\Broadcom Wireless Utility) (Version:  - Broadcom Corporation)
CyberLink PowerDVD 12 (HKLM-x32\…\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.2.3115 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 4.2.1.4224 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Energy Star (HKLM-x32\…\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 45.0.2454.85 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.13 - Google Inc.) Hidden
Hewlett-Packard ACLM.NET v1.2.2.1 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP 3D DriveGuard (HKLM-x32\…\{07F6DC37-0857-4B68-A675-4E35989E85E3}) (Version: 6.0.15.1 - Hewlett-Packard Company)
HP Client Security Manager (HKLM\…\HPProtectTools) (Version: 8.2.0.1663 - Hewlett-Packard Company)
HP Connection Manager (HKLM-x32\…\{7ED7BF91-D145-480A-B206-6891576F6935}) (Version: 4.6.12.1 - Hewlett-Packard Company)
HP Device Access Manager (HKLM\…\{9F7FF800-8C11-4741-8D20-92E43CA02FD6}) (Version: 8.2.0.10 - Hewlett-Packard Company)
HP Documentation (HKLM-x32\…\{2032D55B-645D-4A90-98B0-F5C9B20B9537}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Drive Encryption (HKLM\…\HPDriveEncryption) (Version: 8.6.1.160 - Hewlett-Packard Company)
HP ESU for Microsoft Windows 7 (HKLM-x32\…\{240B2BF7-E7E6-425C-A2A4-A3149189BF7F}) (Version: 2.3.1 - Hewlett-Packard Company)
HP File Sanitizer (HKLM-x32\…\{547607B0-3294-4ECA-8F5E-921404676CBB}) (Version: 8.4.11.1 - Hewlett-Packard Company)
HP HD Webcam Driver (HKLM-x32\…\Sunplus SPUVCb) (Version: 3.4.8.28 - SunplusIT)
HP Hotkey Support (HKLM-x32\…\{C807BEFB-0F17-41AC-B307-D7B5E1553040}) (Version: 5.0.20.1 - Hewlett-Packard Company)
HP PageLift (HKLM-x32\…\{708ABF62-5D7A-4550-823A-1F9EFA63645A}) (Version: 1.0.11.1 - Hewlett-Packard Company)
HP Setup (HKLM-x32\…\{438363A8-F486-4C37-834C-4955773CB3D3}) (Version: 9.1.15453.4066 - Hewlett-Packard Company)
HP SoftPaq Download Manager (HKLM-x32\…\{5C2D96B7-0468-4450-8BD9-63AB796D72CF}) (Version: 3.4.11.0 - Hewlett-Packard Company)
HP Software Setup (HKLM-x32\…\{10CCDB7D-D5E9-45BF-8E7A-004398AE04A0}) (Version: 8.7.2.1 - Hewlett-Packard Company)
HP Support Assistant (HKLM-x32\…\{C88F84E5-AE23-44BD-922C-2ABEACACAF7A}) (Version: 7.2.23.56 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\…\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 13.00.0000 - Hewlett-Packard)
HP System Default Settings (HKLM-x32\…\{3A61A282-4F08-4D43-920C-DC30ECE528E8}) (Version: 2.6.1 - Hewlett-Packard Company)
HP Theft Recovery (HKLM-x32\…\InstallShield_{BAC712C6-4061-4C9F-AB58-A5C53E76704A}) (Version: 8.2.0.9 - Hewlett-Packard Company)
HP Trust Circles (HKLM-x32\…\HP Trust Circles) (Version: 8.2.15.16418 - CryptoMill Technologies)
IDT Audio (HKLM-x32\…\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6486.0 - IDT)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.12.1688 - Intel Corporation)
Intel(R) Network Connections Drivers (HKLM\…\PROSet) (Version: 18.5 - Intel)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.18.10.3324 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.7.3.1001 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.66956 - Intel Corporation)
Intel(R) Smart Connect Technology (HKLM\…\{5EC1901C-D946-424C-9E77-4F58F64C987B}) (Version: 4.2.40.2384 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\…\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation)
iTunes (HKLM\…\{6CF1A7E2-8001-4870-9F18-3C6CDD6FE9E3}) (Version: 12.2.1.16 - Apple Inc.)
LEGO Racers (HKLM-x32\…\LEGO Racers) (Version:  - )
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
McAfee SecurityCenter (HKLM-x32\…\MSC) (Version: 14.0.1029 - McAfee, Inc.)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM-x32\…\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Zoo Tycoon (HKLM-x32\…\Zoo Tycoon 1.0) (Version:  - )
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
opensource (x32 Version: 1.0.14960.3876 - Your Company Name) Hidden
Outils de vérification linguistique 2013 de Microsoft Office - Français (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Pac-Man Adventures in Time (HKLM-x32\…\{D2023740-9AAC-11D4-B54D-006008571948}) (Version:  - )
PDF Complete Corporate Edition (HKLM-x32\…\PDF Complete) (Version: 4.1.50 - PDF Complete, Inc)
Pivot Animator version 4.1.10 (HKLM-x32\…\Pivot Animator_is1) (Version: 4.1.10 - Motus Software Ltd)
Pivot StickFigure Animator Packages (HKU\S-1-5-21-2887876563-769068690-2455426777-1001\…\Pivot StickFigure Animator Packages) (Version:  - ) <==== ATTENTION
Pivot Stickfigure Animator version 2.2.7 (HKLM-x32\…\Pivot Stickfigure Animator_is1) (Version: 2.2.7 - )
Python 3.2.1 (64-bit) (HKLM\…\{34b2530c-6349-4292-9dc3-60bda4aed93d}) (Version: 3.2.1150 - Python Software Foundation)
Python 3.4 pygame-1.9.2a0 (HKLM-x32\…\{F6025B65-59B9-476B-8CC5-37F95020EBF5}) (Version: 1.9.2 - Pete Shinners, Rene Dudfield, Marcus von Appen, Bob Pendleton, others…)
Python 3.4.2 (HKLM-x32\…\{2583CDBA-8A53-4622-BB67-1D163714C1B4}) (Version: 3.4.16349 - Python Software Foundation)
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 1.1.9200.22 - Realtek Semiconductor Corp.)
Skype™ 7.0 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 17.0.8.3 - Synaptics Incorporated)
Update for Skype for Business 2015 (KB2889853) 32-Bit Edition (HKLM-x32\…\{90150000-012B-0409-0000-0000000FF1CE}_Office15.PROPLUSR_{BF1B3F01-93F3-4B83-93DB-132EB1AED259}) (Version:  - Microsoft)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Restore Points =========================
 
26-08-2015 08:03:25 Windows Update
29-08-2015 11:33:25 Windows Update
02-09-2015 09:19:21 Windows Update
06-09-2015 08:38:43 Windows Update
09-09-2015 14:44:41 Windows Update
09-09-2015 22:52:47 Installed Blackboard Collaborate Launcher
09-09-2015 23:39:05 Installed Blackboard Collaborate Launcher
13-09-2015 19:15:54 Removed Blackboard Collaborate Launcher
14-09-2015 06:10:32 Windows Update
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 19:34 - 2015-09-21 21:56 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {1923DDFD-FCB3-42DC-8980-A6F59EB79488} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-06-07] (Hewlett-Packard Company)
Task: {1A1FEDE0-4117-4E1F-8004-3D9C3E65B3E9} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {1A998E26-F979-45A5-8E57-5558B0B2D300} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-21] (Microsoft Corporation)
Task: {2933EAFF-1F3D-4C5C-BC33-709DB757B697} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2012-11-29] (Hewlett-Packard Company)
Task: {44E0A612-04CC-4954-9CB0-91245B0639C5} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-21] (Microsoft Corporation)
Task: {5650C1CA-0F2F-42EA-B8AB-1DB11FEB1FB2} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {5BCAD4CE-47DB-435C-BBA6-151FC63E4AE1} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {5C9C2738-A906-4DF5-89B5-042122909643} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-06-07] (Hewlett-Packard Company)
Task: {72AE8555-A22B-4471-A7D8-5531AB07C596} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-08] (Adobe Systems Incorporated)
Task: {B51AF5A1-EA92-42ED-9B4C-3C07B6BD5318} - System32\Tasks\Registration => C:\Program Files (x86)\Hewlett-Packard\HP Setup\Dependencies\RemEngine.exe [2012-03-21] ()
Task: {C9652D03-85B3-40BC-BED3-B8CA697379BF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {CB646EBD-FB21-4E77-9001-E20DD21C43EC} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe [2015-06-01] (McAfee, Inc.)
Task: {F106215B-0764-447F-A203-3485B02E9BD4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {FFCDCDBA-AEA7-4FDE-89A2-E82287C79739} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-03-18 14:08 - 2015-03-18 14:08 - 08898720 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2013-08-07 14:01 - 2013-08-07 14:01 - 02654936 _____ () C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\ShredContextMenu.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\SRE Lab\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.150.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{7417BCF3-AB07-4BC9-B3D9-2F3BEB4116AB}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{60FA57F2-317C-42B7-98DD-C8848CF3E4CD}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{166EB59E-6BD1-434A-8088-CE5A661A1837}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{67363868-08C2-4C6C-8E77-B10D2BE09EA1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{0DB0608F-F1A5-4AE2-9066-E7782E70BB22}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{5CF1684F-A688-4FD5-BEB1-175B0A6E8BC0}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe
FirewallRules: [{6D360A95-571D-4859-80A1-583E8A24A201}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe
FirewallRules: [{E4E1C1E9-09C0-4042-852B-465C7961E6C0}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
FirewallRules: [{E04F7CCA-D0C4-4BBF-8965-2637D6D09702}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe
FirewallRules: [{634BCD9C-CB37-4E91-A6C3-A38AC4979681}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{A979F43E-7F43-4083-B3DD-2432455D9330}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [{4D18D2AB-3EE8-450F-BCC5-2820E15BFAFD}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{521A06B7-981B-443C-8C39-0F741FC0D681}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{3B76E00C-0A04-4D5F-852D-A1DAD86317D8}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{88E6FBAD-57AC-4B4D-BD27-214BD467EFBC}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{C6603EB4-C006-4B53-ABAD-950CFDFE469D}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{13658905-AA76-430D-B989-F653951418BF}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [TCP Query User{0D745C17-17E2-4214-8AA2-2EE93AE8BAB4}C:\users\sre lab\desktop\dawn of war\w40k.exe] => (Block) C:\users\sre lab\desktop\dawn of war\w40k.exe
FirewallRules: [UDP Query User{68A0CBAA-604D-46C2-96AF-5887CDDC102C}C:\users\sre lab\desktop\dawn of war\w40k.exe] => (Block) C:\users\sre lab\desktop\dawn of war\w40k.exe
FirewallRules: [{B759129C-3E98-45A1-A327-C7F7E60140FC}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{8B642EBB-B46C-4468-B8E8-AAE3918FFE00}] => (Allow) LPort=2869
FirewallRules: [{3988C02D-30AD-4A81-A82F-BF8156C20FF5}] => (Allow) LPort=1900
FirewallRules: [{41E5BFF8-A718-4B53-B0A6-E815B36CE12C}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{C7A436FD-E582-4ECA-A956-A400A1951981}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{CB6EA577-B071-41FB-B6A2-A9A317E8E25B}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{673FB490-1C18-4932-972C-1E9F76E6DA8B}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{0E2FE106-70A5-482C-976B-48372658F80D}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{731B1686-B76E-49DF-ADAE-DD4C79FE0B57}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Faulty Device Manager Devices =============
 
Name: Microsoft Teredo Tunneling Adapter
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
Name: Security Processor Loader Driver
Description: Security Processor Loader Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: spldr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (09/21/2015 10:16:26 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Users\SRE Lab\AppData\Local\Temp\jrt\CreateRestorePoint.exe Lab\AppData\Local\Temp\jrt\CreateRestorePoint.exe"  "JRT Pre-Junkware Removal"; Description = JRT Pre-Junkware Removal; Error = 0x8007043c).
 
Error: (09/21/2015 10:13:45 PM) (Source: AVLogEvent) (EventID: 5010) (User: NT AUTHORITY)
Description: McShield failed to start because it is not trusted.
Error Code:a7f40905
 
Error: (09/21/2015 10:13:45 PM) (Source: AVLogEvent) (EventID: 5007) (User: NT AUTHORITY)
Description: Failed to load a dependant module.
Error Code:a7f42003
 
Error: (09/21/2015 10:01:18 PM) (Source: AVLogEvent) (EventID: 5010) (User: NT AUTHORITY)
Description: McShield failed to start because it is not trusted.
Error Code:a7f40905
 
Error: (09/21/2015 10:01:18 PM) (Source: AVLogEvent) (EventID: 5007) (User: NT AUTHORITY)
Description: Failed to load a dependant module.
Error Code:a7f42003
 
Error: (09/21/2015 09:51:49 PM) (Source: AVLogEvent) (EventID: 5010) (User: NT AUTHORITY)
Description: McShield failed to start because it is not trusted.
Error Code:a7f40905
 
Error: (09/21/2015 09:51:49 PM) (Source: AVLogEvent) (EventID: 5007) (User: NT AUTHORITY)
Description: Failed to load a dependant module.
Error Code:a7f42003
 
Error: (09/21/2015 09:45:51 PM) (Source: ESENT) (EventID: 481) (User: )
Description: Windows (1312) Windows: An attempt to read from the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log" at offset 4096 (0x0000000000001000) for 1044480 (0x000ff000) bytes failed after Windows0 seconds with system error 23 (0x00000017): "Data error (cyclic redundancy check). ".  The read operation will fail with error -1021 (0xfffffc03).  If this error persists then the file may be damaged and may need to be restored from a previous backup.
 
Error: (09/21/2015 09:40:48 PM) (Source: ESENT) (EventID: 465) (User: )
Description: Windows (1312) Windows: Corruption was detected during soft recovery in logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log. The failing checksum record is located at position END. Data not matching the log-file fill pattern first appeared in sector 191 (0x000000BF). This logfile has been damaged and is unusable.
 
Error: (09/21/2015 09:40:48 PM) (Source: ESENT) (EventID: 481) (User: )
Description: Windows (1312) Windows: An attempt to read from the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log" at offset 782336 (0x00000000000bf000) for 4096 (0x00001000) bytes failed after Windows0 seconds with system error 23 (0x00000017): "Data error (cyclic redundancy check). ".  The read operation will fail with error -1021 (0xfffffc03).  If this error persists then the file may be damaged and may need to be restored from a previous backup.
 
 
System errors:
=============
Error: (09/22/2015 08:39:22 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/22/2015 08:39:22 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/22/2015 08:39:22 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/22/2015 08:39:22 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/22/2015 08:39:22 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/22/2015 08:39:22 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/22/2015 08:39:22 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/22/2015 08:39:22 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/22/2015 08:39:22 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/22/2015 08:39:22 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i5-4200U CPU @ 1.60GHz
Percentage of memory in use: 15%
Total physical RAM: 7833.11 MB
Available physical RAM: 6639.35 MB
Total Virtual: 15664.42 MB
Available Virtual: 14550.49 MB
 
==================== Drives ================================
 
Drive c: (Windows) (Fixed) (Total:451.31 GB) (Free:367.17 GB) NTFS
Drive d: (HP_RECOVERY) (Fixed) (Total:11.45 GB) (Free:1.27 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive e: (HP_TOOLS) (Fixed) (Total:1.99 GB) (Free:1.98 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 0FE3875A)
Partition 1: (Active) - (Size=1 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=451.3 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=11.4 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=2 GB) - (Type=0B)
 
==================== End of Addition.txt ============================
 

Good Morning,

 

First see if you can run this fix in Normal windows, if not than Safemode

 

 

 
Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist, Save it to your desktop where you have FRST/FRST64 or the fix wont work, . Then open up FRST/FRST64 and click on FIX (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
 
Start
CloseProcesses:
CreateRestorePoint: 
AppInit_DLLs: C:\Program Files => C:\Program Files [0 2015-07-14] ()
AppInit_DLLs-x32: C:\Program Files => C:\Program Files [0 2015-07-14] ()
Startup: C:\Users\SRE Lab\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PowerReg Scheduler.exe [2014-09-23] ()
Hosts:
CMD: ipconfig /flushdns
EmptyTemp:
End
 
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Couldn't run after normal boot, so ran in Safe Mode.

 

Fix result of Farbar Recovery Scan Tool (x64) Version:23-09-2015
Ran by [removed] (2015-09-23 08:06:50) Run:2
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Safe Mode (with Networking)
==============================================
 
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint: 
AppInit_DLLs: C:\Program Files => C:\Program Files [0 2015-07-14] ()
AppInit_DLLs-x32: C:\Program Files => C:\Program Files [0 2015-07-14] ()
Startup: C:\Users\SRE Lab\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PowerReg Scheduler.exe [2014-09-23] ()
Hosts:
CMD: ipconfig /flushdns
EmptyTemp:
End
 
*****************
 
Processes closed successfully.
Error: Restore point can only be created in normal mode.
"C:\Program Files" => Value data removed successfully.
"C:\Program Files" => Value data removed successfully.
C:\Users\SRE Lab\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PowerReg Scheduler.exe => moved successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
 
=========  ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
EmptyTemp: => 28.4 MB temporary data Removed.
 
 
The system needed a reboot.. 
 
==== End of Fixlog 08:06:54 ====

No. When I boot normally, the system hangs for several minutes at a time. For instance, I booted three minutes ago, but I can't run anything or select anything. The System Tray is fully populated as it should be, but I can't even get to Task Manager–once I get to a point where I can select it, I'm returned to the Desktop without TM running.

Finally got TM to launch. Shows CPU usage under 10% and physical memory under 20%, so plenty of CPU and RAM.

Just launched Chrome and an now waiting for it to launch.

Lets run a couple of different programs, safemode is fine and if they find nothing than i will link you to our windows forum as it may be windows related…at this point not sure.  Let me ask you when this started, was it something you downloaded and installed or added new hardware to your system ?? There is a nice free online virus scanner that may pick up something that the other scanners missed, Safemode with Networking will be needed because it needs to go out and get updates, if it wont run then forget it and go on to the other two

 

  

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan
 
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.
 
 
  •  
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
  • Click the [external image: esetOnline.png] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    •  
  • Click on [external image: esetSmartInstall.png] to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the [external image: esetSmartInstallDesktopIcon.png] icon on your desktop.
 
  • Check [external image: esetAcceptTerms.png]
  • Click the [external image: esetStart.png] button.
  • Accept any security warnings from your browser.
  • Check [external image: esetScanArchives.png]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: esetListThreats.png]
  • Push [external image: esetExport.png], and save the file to your desktop using a unique name, such as
ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: esetBack.png] button.
  • Push [external image: esetFinish.png]
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.
 
 
 
==========================================================
 
 

Please download Malwarebytes Anti-Rootkit from Here
  •  
  • Unzip the contents to a folder in a convenient location.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • When done, please post the two logs produced they will be in the MBAR folder… mbar-log.txt and system-log.txt
 
 
 
 
 
===================================================
 
 

–RogueKiller–
 
  •  
  • Download & SAVE to your Desktop RogueKiller or 32 BIT
  • Quit all programs that you may have started.
  • Please disconnect any USB or external drives from the computer before you run this scan!
  • For Vista or Windows 7,  right-click and select "Run as  Administrator to start"
  • For Windows XP, double-click to start.
  • Wait until Prescan has finished …
  • Then Click on "Scan" button
  • Wait until the Status box shows "Scan Finished"
  • Click on "Report" and copy/paste the content of the Notepad into your next reply.
  • The log should be found in RKreport[1].txt on your Desktop
  • Exit/Close RogueKiller+
 
 
 

 

ESET only found three quarantined problems from AdwCleaner. Couldn't save the export file, as the ESET window was too small and wouldn't allow me to navigate and see within it.

 

MBAR didn't find anything.

 

RogueKiller blew up twice, during the file scan. I could not get it to finish.

 

Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org
 
Database version:
  main:    v0000.00.00.00
  rootkit: v0000.00.00.00
 
Windows 7 Service Pack 1 x64 NTFS (Safe Mode/Networking)
Internet Explorer 11.0.9600.18015
SRE Lab :: SRELAB-HP [administrator]
 
9/23/2015 4:14:26 PM
mbar-log-2015-09-23 (16-14-26).txt
 
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: 
Objects scanned: 1400
Time elapsed: 54 second(s)
 
Memory Processes Detected: 0
(No malicious items detected)
 
Memory Modules Detected: 0
(No malicious items detected)
 
Registry Keys Detected: 0
(No malicious items detected)
 
Registry Values Detected: 0
(No malicious items detected)
 
Registry Data Items Detected: 0
(No malicious items detected)
 
Folders Detected: 0
(No malicious items detected)
 
Files Detected: 0
(No malicious items detected)
 
Physical Sectors Detected: 0
(No malicious items detected)
 
(end)
 
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 
 
 M a l w a r e b y t e s   A n t i - R o o t k i t   B E T A   1 . 0 9 . 3 . 1 0 0 1 
 
 
 
 ( c )   M a l w a r e b y t e s   C o r p o r a t i o n   2 0 1 1 - 2 0 1 2 
 
 
 
 O S   v e r s i o n :   6 . 1 . 7 6 0 1   W i n d o w s   7   S e r v i c e   P a c k   1   x 6 4 
 
 
 
 S y s t e m   i s   c u r r e n t l y   i n   a   s a f e   m o d e 
 
 
 
 A c c o u n t   i s   A d m i n i s t r a t i v e 
 
 
 
 I n t e r n e t   E x p l o r e r   v e r s i o n :   1 1 . 0 . 9 6 0 0 . 1 8 0 1 5 
 
 
 
 F i l e   s y s t e m   i s :   N T F S 
 
 D i s k   d r i v e s :   C : \   D R I V E _ F I X E D ,   D : \   D R I V E _ F I X E D ,   E : \   D R I V E _ F I X E D 
 
 C P U   s p e e d :   2 . 2 9 4 0 0 0   G H z 
 
 M e m o r y   t o t a l :   8 2 1 3 6 1 0 4 9 6 ,   f r e e :   6 6 2 8 6 8 3 7 7 6 
 
 
 
 = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = 
 
 I n i t i a l i z i n g . . . 
 
 D r i v e r   v e r s i o n :   0 . 3 . 0 . 4 
 
 - - - - - - - - - - - -   K e r n e l   r e p o r t   - - - - - - - - - - - - 
 
           0 9 / 2 3 / 2 0 1 5   1 6 : 1 4 : 2 3 
 
 - - - - - - - - - - - -   L o a d e d   m o d u l e s   - - - - - - - - - - - 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ n t o s k r n l . e x e 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ h a l . d l l 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ k d c o m . d l l 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ m c u p d a t e _ G e n u i n e I n t e l . d l l 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ P S H E D . d l l 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ C L F S . S Y S 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ C I . d l l 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ W d f 0 1 0 0 0 . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ W D F L D R . S Y S 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ A C P I . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ W M I L I B . S Y S 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ m s i s a d r v . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ p c i . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ v d r v r o o t . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ i u s b 3 h c s . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ i s a p n p . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ m p i o . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ d r i v e r s \ p a r t m g r . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ c o m p b a t t . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ B A T T C . S Y S 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ v o l m g r . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ d r i v e r s \ v o l m g r x . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ i n t e l i d e . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ P C I I D E X . S Y S 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ S D D T o k i . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ a l i i d e . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ a m d i d e . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ c m d i d e . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ d r i v e r s \ m o u n t m g r . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ m s d s m . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ n v r a i d . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ C L A S S P N P . S Y S 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ p c i i d e . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ v i a i d e . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ v m b u s . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ w i n h v . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ i a S t o r V . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ a t a p i . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ a t a p o r t . S Y S 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ l s i _ s a s . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ s t o r p o r t . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ m s a h c i . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ i a S t o r A . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ H p S A M D . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ a d p 9 4 x x . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ a d p a h c i . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ a d p u 3 2 0 . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ a m d s a t a . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ a m d s b s . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ a m d x a t a . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ a r c . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ a r c s a s . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ e l x s t o r . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ i i r s p . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ l s i _ f c . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ l s i _ s a s 2 . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ l s i _ s c s i . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ m e g a s a s . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ M e g a S R . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ n f r d 9 6 0 . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ n v s t o r . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ q l 2 3 0 0 . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ q l 4 0 x x . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ S i S R a i d 2 . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ s i s r a i d 4 . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ s t e x s t o r . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ v s m r a i d . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ f l t m g r . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ P i n F i l e . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ f i l e i n f o . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ m f e h i d k . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ S D D i s k 2 K . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ D r i v e r s \ N t f s . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ D r i v e r s \ m s r p c . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ D r i v e r s \ k s e c d d . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ D r i v e r s \ c n g . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ d r i v e r s \ p c w . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ s t o r v s c . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ D r i v e r s \ F s _ R e c . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ n d i s . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ N E T I O . S Y S 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ D r i v e r s \ k s e c p k g . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ d r i v e r s \ t c p i p . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ d r i v e r s \ f w p k c l n t . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ m f e w f p k . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ v m s t o r f l . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ w d . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ v o l s n a p . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ s b p 2 p o r t . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ d r i v e r s \ r d y b o o s t . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ D r i v e r s \ m u p . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ m f e d i s k . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ i a S t o r F . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ d r i v e r s \ h w p o l i c y . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ h p d s k f l t . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ D R I V E R S \ f v e v o l . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ d i s k . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ D r i v e r s \ N u l l . S Y S 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ D r i v e r s \ B e e p . S Y S 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ d r i v e r s \ v g a . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ d r i v e r s \ V I D E O P R T . S Y S 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ d r i v e r s \ w a t c h d o g . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ r d p e n c d d . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ D r i v e r s \ M s f s . S Y S 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ D r i v e r s \ N p f s . S Y S 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ t d x . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ T D I . S Y S 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ D R I V E R S \ n e t b t . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ a f d . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ w f p l w f . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ p a c e r . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ v w i f i f l t . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ n e t b i o s . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ r d b s s . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ n s i p r o x y . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ c s c . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ D r i v e r s \ d f s c . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ H D A u d B u s . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ i u s b 3 x h c . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ U S B D . S Y S 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ T e e D r i v e r x 6 4 . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ e 1 d 6 2 x 6 4 . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ b c m w l 6 6 4 . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ v w i f i b u s . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ u s b e h c i . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ U S B P O R T . S Y S 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ D r i v e r s \ f a s t f a t . S Y S 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ i 8 0 4 2 p r t . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ H p q K b F i l t r . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ i k b e v e n t . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ S y n T P . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ k b d c l a s s . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ i m s e v e n t . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ m o u c l a s s . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ S m b _ d r i v e r _ I n t e l . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ A c c e l e r o m e t e r . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ w m i a c p i . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ t p m . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ I S C T D 6 4 . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ b l b d r i v e . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ C o m p o s i t e B u s . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ m s s m b i o s . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ A g i l e V p n . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ r a s l 2 t p . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ n d i s t a p i . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ n d i s w a n . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ r a s p p p o e . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ r a s p p t p . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ r a s s s t p . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ r d p b u s . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ t e r m d d . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ s w e n u m . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ k s . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ u m b u s . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ u s b h u b . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ D r i v e r s \ N D P r o x y . S Y S 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ i u s b 3 h u b . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ D r i v e r s \ c r a s h d m p . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ D r i v e r s \ d u m p _ d i s k d u m p . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ D r i v e r s \ d u m p _ i a S t o r A . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ D r i v e r s \ d u m p _ W M S D F V E . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ D r i v e r s \ d u m p _ d u m p f v e . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ w i n 3 2 k . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ d r i v e r s \ D x a p i . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ d r i v e r s \ d x g . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ u s b c c g p . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ T S D D D . d l l 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ f r a m e b u f . d l l 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ n w i f i . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ n d i s u i o . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ b o w s e r . s y s 
 
 \ S y s t e m R o o t \ S y s t e m 3 2 \ d r i v e r s \ m p s d r v . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ m r x s m b . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ m r x s m b 1 0 . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ m r x s m b 2 0 . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ m f e a a c k . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ m f e f i r e k . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ D R I V E R S \ v w i f i m p . s y s 
 
 \ S y s t e m R o o t \ s y s t e m 3 2 \ d r i v e r s \ c f w i d s . s y s 
 
 \ ? ? \ C : \ W i n d o w s \ s y s t e m 3 2 \ d r i v e r s \ m b a m c h a m e l e o n . s y s 
 
 \ ? ? \ C : \ W i n d o w s \ s y s t e m 3 2 \ d r i v e r s \ M B A M S w i s s A r m y . s y s 
 
 \ W i n d o w s \ S y s t e m 3 2 \ n t d l l . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ s m s s . e x e 
 
 \ W i n d o w s \ S y s t e m 3 2 \ a p i s e t s c h e m a . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ a u t o c h k . e x e 
 
 \ W i n d o w s \ S y s t e m 3 2 \ c l b c a t q . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ r p c r t 4 . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ d i f x a p i . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ s h e l l 3 2 . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ i e r t u t i l . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ o l e 3 2 . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ u s p 1 0 . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ m s c t f . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ i m a g e h l p . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ u r l m o n . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ l p k . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ W l d a p 3 2 . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ o l e a u t 3 2 . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ u s e r 3 2 . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ s h l w a p i . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ a d v a p i 3 2 . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ n o r m a l i z . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ m s v c r t . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ p s a p i . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ g d i 3 2 . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ s e c h o s t . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ w i n i n e t . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ n s i . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ k e r n e l 3 2 . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ c o m d l g 3 2 . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ w s 2 _ 3 2 . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ i m m 3 2 . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ s e t u p a p i . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ a p i - m s - w i n - d o w n l e v e l - v e r s i o n - l 1 - 1 - 0 . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ d e v o b j . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ w i n t r u s t . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ a p i - m s - w i n - d o w n l e v e l - a d v a p i 3 2 - l 1 - 1 - 0 . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ a p i - m s - w i n - d o w n l e v e l - s h l w a p i - l 1 - 1 - 0 . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ u s e r e n v . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ K e r n e l B a s e . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ a p i - m s - w i n - d o w n l e v e l - n o r m a l i z - l 1 - 1 - 0 . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ c f g m g r 3 2 . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ a p i - m s - w i n - d o w n l e v e l - o l e 3 2 - l 1 - 1 - 0 . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ a p i - m s - w i n - d o w n l e v e l - u s e r 3 2 - l 1 - 1 - 0 . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ c r y p t 3 2 . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ c o m c t l 3 2 . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ p r o f a p i . d l l 
 
 \ W i n d o w s \ S y s t e m 3 2 \ m s a s n 1 . d l l 
 
 - - - - - - - - - - -   E n d   - - - - - - - - - - - 
 
 D o n e ! 
 
 
 
 S c a n   s t a r t e d 
 
 D a t a b a s e   v e r s i o n s : 
 
     m a i n :         v 0 0 . 0 0 . 0 0 . 0 0 
 
     r o o t k i t :   v 0 0 . 0 0 . 0 0 . 0 0 
 
 
 
 < < < 2 > > > 
 
 P h y s i c a l   S e c t o r   S i z e :   5 1 2 
 
 D r i v e :   0 ,   D e v i c e P o i n t e r :   0 x f f f f f a 8 0 0 a 1 6 8 0 6 0 ,   D e v i c e N a m e :   \ D e v i c e \ H a r d d i s k 0 \ D R 0 \ ,   D r i v e r N a m e :   \ D r i v e r \ D i s k \ 
 
 - - - - - - - - -   D i s k   S t a c k   - - - - - - 
 
 D e v i c e P o i n t e r :   0 x f f f f f a 8 0 0 7 d 5 9 9 d 0 ,   D e v i c e N a m e :   U n k n o w n ,   D r i v e r N a m e :   \ D r i v e r \ p a r t m g r \ 
 
 D e v i c e P o i n t e r :   0 x f f f f f a 8 0 0 a 1 6 9 0 4 0 ,   D e v i c e N a m e :   U n k n o w n ,   D r i v e r N a m e :   \ D r i v e r \ S D D i s k 2 K \ 
 
 D e v i c e P o i n t e r :   0 x f f f f f a 8 0 0 a 1 6 8 0 6 0 ,   D e v i c e N a m e :   \ D e v i c e \ H a r d d i s k 0 \ D R 0 \ ,   D r i v e r N a m e :   \ D r i v e r \ D i s k \ 
 
 D e v i c e P o i n t e r :   0 x f f f f f a 8 0 0 7 d 5 8 b 1 0 ,   D e v i c e N a m e :   U n k n o w n ,   D r i v e r N a m e :   \ D r i v e r \ h p d s k f l t \ 
 
 D e v i c e P o i n t e r :   0 x f f f f f a 8 0 0 7 d 5 4 c 5 0 ,   D e v i c e N a m e :   U n k n o w n ,   D r i v e r N a m e :   \ D r i v e r \ i a S t o r F \ 
 
 D e v i c e P o i n t e r :   0 x f f f f f a 8 0 0 7 b 0 2 6 c 0 ,   D e v i c e N a m e :   \ D e v i c e \ 0 0 0 0 0 0 9 a \ ,   D r i v e r N a m e :   \ D r i v e r \ i a S t o r A \ 
 
 - - - - - - - - - - - -   E n d   - - - - - - - - - - 
 
 A l t e r n a t e   D e v i c e N a m e :   U n k n o w n ,   D r i v e r N a m e :   \ D r i v e r \ S D D i s k 2 K \ 
 
 U p p e r   D e v i c e D a t a :   0 x 0 ,   0 x 0 ,   0 x 0 
 
 L o w e r   D e v i c e D a t a :   0 x 0 ,   0 x 0 ,   0 x 0 
 
 < < < 3 > > > 
 
 V o l u m e :   C : 
 
 F i l e   s y s t e m   t y p e :   N T F S 
 
 S e c t o r S i z e   =   5 1 2 ,   C l u s t e r S i z e   =   4 0 9 6 ,   M F T R e c o r d S i z e   =   1 0 2 4 ,   M F T I n d e x S i z e   =   4 0 9 6   b y t e s 
 
 < < < 2 > > > 
 
 < < < 3 > > > 
 
 V o l u m e :   C : 
 
 F i l e   s y s t e m   t y p e :   N T F S 
 
 S e c t o r S i z e   =   5 1 2 ,   C l u s t e r S i z e   =   4 0 9 6 ,   M F T R e c o r d S i z e   =   1 0 2 4 ,   M F T I n d e x S i z e   =   4 0 9 6   b y t e s 
 
 S c a n n i n g   d r i v e r s   d i r e c t o r y :   C : \ W I N D O W S \ S Y S T E M 3 2 \ d r i v e r s . . . 
 
 F i l e   u s e r   o p e n   f a i l e d :   C : \ W I N D O W S \ S Y S T E M 3 2 \ d r i v e r s \ P i n F i l e L o g . l o g   ( 0 x 0 0 0 0 0 0 2 0 ) 
 
 D o n e ! 
 
 D r i v e   0 
 
 T h i s   i s   a   S y s t e m   d r i v e 
 
 S c a n n i n g   M B R   o n   d r i v e   0 . . . 
 
 I n s p e c t i n g   p a r t i t i o n   t a b l e : 
 
 M B R   S i g n a t u r e :   5 5 A A 
 
 D i s k   S i g n a t u r e :   F E 3 8 7 5 A 
 
 
 
 P a r t i t i o n   i n f o r m a t i o n : 
 
 
 
         P a r t i t i o n   0   t y p e   i s   P r i m a r y   ( 0 x 7 ) 
 
         P a r t i t i o n   i s   A C T I V E . 
 
         P a r t i t i o n   s t a r t s   a t   L B A :   2 0 4 8     N u m s e c   =   2 0 9 9 2 0 0 
 
         P a r t i t i o n   i s   b o o t a b l e 
 
         P a r t i t i o n   f i l e   s y s t e m   i s   N T F S 
 
 
 
         P a r t i t i o n   1   t y p e   i s   P r i m a r y   ( 0 x 7 ) 
 
         P a r t i t i o n   i s   N O T   A C T I V E . 
 
         P a r t i t i o n   s t a r t s   a t   L B A :   2 1 0 1 2 4 8     N u m s e c   =   9 4 6 4 6 2 7 2 0 
 
         P a r t i t i o n   i s   n o t   b o o t a b l e 
 
         P a r t i t i o n   f i l e   s y s t e m   i s   N T F S 
 
 
 
         P a r t i t i o n   2   t y p e   i s   P r i m a r y   ( 0 x 7 ) 
 
         P a r t i t i o n   i s   N O T   A C T I V E . 
 
         P a r t i t i o n   s t a r t s   a t   L B A :   9 4 8 5 6 3 9 6 8     N u m s e c   =   2 4 0 0 4 6 0 8 
 
         P a r t i t i o n   i s   n o t   b o o t a b l e 
 
         P a r t i t i o n   f i l e   s y s t e m   i s   N T F S 
 
 
 
         P a r t i t i o n   3   t y p e   i s   O t h e r   ( 0 x b ) 
 
         P a r t i t i o n   i s   N O T   A C T I V E . 
 
         P a r t i t i o n   s t a r t s   a t   L B A :   9 7 2 5 6 8 5 7 6     N u m s e c   =   4 1 9 4 3 0 4 
 
         P a r t i t i o n   i s   n o t   b o o t a b l e 
 
         P a r t i t i o n   f i l e   s y s t e m   i s   F A T 3 2 
 
 
 
 D i s k   S i z e :   5 0 0 1 0 7 8 6 2 0 1 6   b y t e s 
 
 S e c t o r   s i z e :   5 1 2   b y t e s 
 
 
 
 D o n e ! 
 
 S c a n   f i n i s h e d 
 
 = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = 
 
 
 
 
 
 R e m o v a l   q u e u e   f o u n d ;   r e m o v a l   s t a r t e d 
 
 R e m o v i n g   C : \ P r o g r a m D a t a \ M a l w a r e b y t e s '   A n t i - M a l w a r e   ( p o r t a b l e ) \ M B R - 0 - i . m b a m . . . 
 
 R e m o v i n g   C : \ P r o g r a m D a t a \ M a l w a r e b y t e s '   A n t i - M a l w a r e   ( p o r t a b l e ) \ V B R - 0 - 0 - 2 0 4 8 - i . m b a m . . . 
 
 R e m o v i n g   C : \ P r o g r a m D a t a \ M a l w a r e b y t e s '   A n t i - M a l w a r e   ( p o r t a b l e ) \ V B R - 0 - 1 - 2 1 0 1 2 4 8 - i . m b a m . . . 
 
 R e m o v i n g   C : \ P r o g r a m D a t a \ M a l w a r e b y t e s '   A n t i - M a l w a r e   ( p o r t a b l e ) \ V B R - 0 - 2 - 9 4 8 5 6 3 9 6 8 - i . m b a m . . . 
 
 R e m o v i n g   C : \ P r o g r a m D a t a \ M a l w a r e b y t e s '   A n t i - M a l w a r e   ( p o r t a b l e ) \ V B R - 0 - 3 - 9 7 2 5 6 8 5 7 6 - i . m b a m . . . 
 
 R e m o v i n g   C : \ P r o g r a m D a t a \ M a l w a r e b y t e s '   A n t i - M a l w a r e   ( p o r t a b l e ) \ M B R - 0 - r . m b a m . . . 
 
 R e m o v a l   f i n i s h e d 
 
 
Let me ask you when this started, was it something you downloaded and installed or added new hardware to your system ?? 

 

 

 

 

Nothing found, starting to believe this is not malware related

 

 

 

Open up FRST, checkmark Additions and run a new scan and post both logs and let me take a final look

Not sure when this started as this is my son's laptop.

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:23-09-2015
Ran by [removed] (2015-09-23 22:01:22)
Running from C:\Users\[removed]\Desktop
Windows 7 Professional Service Pack 1 (X64) (2013-10-24 17:26:14)
Boot Mode: Safe Mode (with Networking)
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-2887876563-769068690-2455426777-500 - Administrator - Disabled)
Guest (S-1-5-21-2887876563-769068690-2455426777-501 - Limited - Disabled)
SRE Lab (S-1-5-21-2887876563-769068690-2455426777-1001 - Administrator - Enabled) => C:\Users\SRE Lab
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: McAfee Anti-Virus and Anti-Spyware (Disabled - Up to date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee Anti-Virus and Anti-Spyware (Disabled - Up to date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
FW: McAfee Firewall (Enabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Flash Player 11 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 11.2.202.228 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.1.5.155 - Adobe Systems, Inc.)
Alcor Micro Smart Card Reader Driver (HKLM-x32\…\SZCCID) (Version: 1.7.35.0 - Alcor Micro Corp.)
Alcor Micro Smart Card Reader Driver (x32 Version: 1.7.35.0 - Alcor Micro Corp.) Hidden
Apple Application Support (32-bit) (HKLM-x32\…\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{B255D495-4734-4E9B-B4F5-96702FD4A7B9}) (Version: 3.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}) (Version: 8.2.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom 802.11 Wireless LAN Adapter (HKLM\…\Broadcom 802.11 Wireless LAN Adapter) (Version:  - Broadcom Corporation)
Broadcom Bluetooth Software (HKLM\…\{A1439D4F-FD46-47F2-A1D3-FEE097C29A09}) (Version: 6.5.1.3700 - Broadcom Corporation)
Broadcom Wireless Utility (HKLM\…\Broadcom Wireless Utility) (Version:  - Broadcom Corporation)
CyberLink PowerDVD 12 (HKLM-x32\…\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.2.3115 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 4.2.1.4224 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Energy Star (HKLM-x32\…\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company)
ESET Online Scanner v3 (HKLM-x32\…\ESET Online Scanner) (Version:  - )
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 45.0.2454.85 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.13 - Google Inc.) Hidden
Hewlett-Packard ACLM.NET v1.2.2.1 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP 3D DriveGuard (HKLM-x32\…\{07F6DC37-0857-4B68-A675-4E35989E85E3}) (Version: 6.0.15.1 - Hewlett-Packard Company)
HP Client Security Manager (HKLM\…\HPProtectTools) (Version: 8.2.0.1663 - Hewlett-Packard Company)
HP Connection Manager (HKLM-x32\…\{7ED7BF91-D145-480A-B206-6891576F6935}) (Version: 4.6.12.1 - Hewlett-Packard Company)
HP Device Access Manager (HKLM\…\{9F7FF800-8C11-4741-8D20-92E43CA02FD6}) (Version: 8.2.0.10 - Hewlett-Packard Company)
HP Documentation (HKLM-x32\…\{2032D55B-645D-4A90-98B0-F5C9B20B9537}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Drive Encryption (HKLM\…\HPDriveEncryption) (Version: 8.6.1.160 - Hewlett-Packard Company)
HP ESU for Microsoft Windows 7 (HKLM-x32\…\{240B2BF7-E7E6-425C-A2A4-A3149189BF7F}) (Version: 2.3.1 - Hewlett-Packard Company)
HP File Sanitizer (HKLM-x32\…\{547607B0-3294-4ECA-8F5E-921404676CBB}) (Version: 8.4.11.1 - Hewlett-Packard Company)
HP HD Webcam Driver (HKLM-x32\…\Sunplus SPUVCb) (Version: 3.4.8.28 - SunplusIT)
HP Hotkey Support (HKLM-x32\…\{C807BEFB-0F17-41AC-B307-D7B5E1553040}) (Version: 5.0.20.1 - Hewlett-Packard Company)
HP PageLift (HKLM-x32\…\{708ABF62-5D7A-4550-823A-1F9EFA63645A}) (Version: 1.0.11.1 - Hewlett-Packard Company)
HP Setup (HKLM-x32\…\{438363A8-F486-4C37-834C-4955773CB3D3}) (Version: 9.1.15453.4066 - Hewlett-Packard Company)
HP SoftPaq Download Manager (HKLM-x32\…\{5C2D96B7-0468-4450-8BD9-63AB796D72CF}) (Version: 3.4.11.0 - Hewlett-Packard Company)
HP Software Setup (HKLM-x32\…\{10CCDB7D-D5E9-45BF-8E7A-004398AE04A0}) (Version: 8.7.2.1 - Hewlett-Packard Company)
HP Support Assistant (HKLM-x32\…\{C88F84E5-AE23-44BD-922C-2ABEACACAF7A}) (Version: 7.2.23.56 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\…\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 13.00.0000 - Hewlett-Packard)
HP System Default Settings (HKLM-x32\…\{3A61A282-4F08-4D43-920C-DC30ECE528E8}) (Version: 2.6.1 - Hewlett-Packard Company)
HP Theft Recovery (HKLM-x32\…\InstallShield_{BAC712C6-4061-4C9F-AB58-A5C53E76704A}) (Version: 8.2.0.9 - Hewlett-Packard Company)
HP Trust Circles (HKLM-x32\…\HP Trust Circles) (Version: 8.2.15.16418 - CryptoMill Technologies)
IDT Audio (HKLM-x32\…\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6486.0 - IDT)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.12.1688 - Intel Corporation)
Intel(R) Network Connections Drivers (HKLM\…\PROSet) (Version: 18.5 - Intel)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.18.10.3324 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.7.3.1001 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 3.0.0.66956 - Intel Corporation)
Intel(R) Smart Connect Technology (HKLM\…\{5EC1901C-D946-424C-9E77-4F58F64C987B}) (Version: 4.2.40.2384 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\…\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation)
iTunes (HKLM\…\{6CF1A7E2-8001-4870-9F18-3C6CDD6FE9E3}) (Version: 12.2.1.16 - Apple Inc.)
LEGO Racers (HKLM-x32\…\LEGO Racers) (Version:  - )
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
McAfee SecurityCenter (HKLM-x32\…\MSC) (Version: 14.0.1029 - McAfee, Inc.)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM-x32\…\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Zoo Tycoon (HKLM-x32\…\Zoo Tycoon 1.0) (Version:  - )
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
opensource (x32 Version: 1.0.14960.3876 - Your Company Name) Hidden
Outils de vérification linguistique 2013 de Microsoft Office - Français (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Pac-Man Adventures in Time (HKLM-x32\…\{D2023740-9AAC-11D4-B54D-006008571948}) (Version:  - )
PDF Complete Corporate Edition (HKLM-x32\…\PDF Complete) (Version: 4.1.50 - PDF Complete, Inc)
Pivot Animator version 4.1.10 (HKLM-x32\…\Pivot Animator_is1) (Version: 4.1.10 - Motus Software Ltd)
Pivot StickFigure Animator Packages (HKU\S-1-5-21-2887876563-769068690-2455426777-1001\…\Pivot StickFigure Animator Packages) (Version:  - ) <==== ATTENTION
Pivot Stickfigure Animator version 2.2.7 (HKLM-x32\…\Pivot Stickfigure Animator_is1) (Version: 2.2.7 - )
Python 3.2.1 (64-bit) (HKLM\…\{34b2530c-6349-4292-9dc3-60bda4aed93d}) (Version: 3.2.1150 - Python Software Foundation)
Python 3.4 pygame-1.9.2a0 (HKLM-x32\…\{F6025B65-59B9-476B-8CC5-37F95020EBF5}) (Version: 1.9.2 - Pete Shinners, Rene Dudfield, Marcus von Appen, Bob Pendleton, others…)
Python 3.4.2 (HKLM-x32\…\{2583CDBA-8A53-4622-BB67-1D163714C1B4}) (Version: 3.4.16349 - Python Software Foundation)
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 1.1.9200.22 - Realtek Semiconductor Corp.)
Skype™ 7.0 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 17.0.8.3 - Synaptics Incorporated)
Update for Skype for Business 2015 (KB2889853) 32-Bit Edition (HKLM-x32\…\{90150000-012B-0409-0000-0000000FF1CE}_Office15.PROPLUSR_{BF1B3F01-93F3-4B83-93DB-132EB1AED259}) (Version:  - Microsoft)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Restore Points =========================
 
26-08-2015 08:03:25 Windows Update
29-08-2015 11:33:25 Windows Update
02-09-2015 09:19:21 Windows Update
06-09-2015 08:38:43 Windows Update
09-09-2015 14:44:41 Windows Update
09-09-2015 22:52:47 Installed Blackboard Collaborate Launcher
09-09-2015 23:39:05 Installed Blackboard Collaborate Launcher
13-09-2015 19:15:54 Removed Blackboard Collaborate Launcher
14-09-2015 06:10:32 Windows Update
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 19:34 - 2015-09-23 08:06 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {1923DDFD-FCB3-42DC-8980-A6F59EB79488} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-06-07] (Hewlett-Packard Company)
Task: {1A1FEDE0-4117-4E1F-8004-3D9C3E65B3E9} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {1A998E26-F979-45A5-8E57-5558B0B2D300} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-21] (Microsoft Corporation)
Task: {2933EAFF-1F3D-4C5C-BC33-709DB757B697} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2012-11-29] (Hewlett-Packard Company)
Task: {44E0A612-04CC-4954-9CB0-91245B0639C5} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-21] (Microsoft Corporation)
Task: {5650C1CA-0F2F-42EA-B8AB-1DB11FEB1FB2} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {5BCAD4CE-47DB-435C-BBA6-151FC63E4AE1} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {5C9C2738-A906-4DF5-89B5-042122909643} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-06-07] (Hewlett-Packard Company)
Task: {72AE8555-A22B-4471-A7D8-5531AB07C596} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-08] (Adobe Systems Incorporated)
Task: {B51AF5A1-EA92-42ED-9B4C-3C07B6BD5318} - System32\Tasks\Registration => C:\Program Files (x86)\Hewlett-Packard\HP Setup\Dependencies\RemEngine.exe [2012-03-21] ()
Task: {C9652D03-85B3-40BC-BED3-B8CA697379BF} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {CB646EBD-FB21-4E77-9001-E20DD21C43EC} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe [2015-06-01] (McAfee, Inc.)
Task: {F106215B-0764-447F-A203-3485B02E9BD4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {FFCDCDBA-AEA7-4FDE-89A2-E82287C79739} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-03-18 14:08 - 2015-03-18 14:08 - 08898720 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2013-08-07 14:01 - 2013-08-07 14:01 - 02654936 _____ () C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\ShredContextMenu.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\SRE Lab\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.150.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{7417BCF3-AB07-4BC9-B3D9-2F3BEB4116AB}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{60FA57F2-317C-42B7-98DD-C8848CF3E4CD}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{166EB59E-6BD1-434A-8088-CE5A661A1837}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{67363868-08C2-4C6C-8E77-B10D2BE09EA1}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{0DB0608F-F1A5-4AE2-9066-E7782E70BB22}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{5CF1684F-A688-4FD5-BEB1-175B0A6E8BC0}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe
FirewallRules: [{6D360A95-571D-4859-80A1-583E8A24A201}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe
FirewallRules: [{E4E1C1E9-09C0-4042-852B-465C7961E6C0}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
FirewallRules: [{E04F7CCA-D0C4-4BBF-8965-2637D6D09702}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe
FirewallRules: [{634BCD9C-CB37-4E91-A6C3-A38AC4979681}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{A979F43E-7F43-4083-B3DD-2432455D9330}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [{4D18D2AB-3EE8-450F-BCC5-2820E15BFAFD}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{521A06B7-981B-443C-8C39-0F741FC0D681}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{3B76E00C-0A04-4D5F-852D-A1DAD86317D8}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{88E6FBAD-57AC-4B4D-BD27-214BD467EFBC}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{C6603EB4-C006-4B53-ABAD-950CFDFE469D}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{13658905-AA76-430D-B989-F653951418BF}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [TCP Query User{0D745C17-17E2-4214-8AA2-2EE93AE8BAB4}C:\users\sre lab\desktop\dawn of war\w40k.exe] => (Block) C:\users\sre lab\desktop\dawn of war\w40k.exe
FirewallRules: [UDP Query User{68A0CBAA-604D-46C2-96AF-5887CDDC102C}C:\users\sre lab\desktop\dawn of war\w40k.exe] => (Block) C:\users\sre lab\desktop\dawn of war\w40k.exe
FirewallRules: [{B759129C-3E98-45A1-A327-C7F7E60140FC}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{8B642EBB-B46C-4468-B8E8-AAE3918FFE00}] => (Allow) LPort=2869
FirewallRules: [{3988C02D-30AD-4A81-A82F-BF8156C20FF5}] => (Allow) LPort=1900
FirewallRules: [{41E5BFF8-A718-4B53-B0A6-E815B36CE12C}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{C7A436FD-E582-4ECA-A956-A400A1951981}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{CB6EA577-B071-41FB-B6A2-A9A317E8E25B}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{673FB490-1C18-4932-972C-1E9F76E6DA8B}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{0E2FE106-70A5-482C-976B-48372658F80D}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{731B1686-B76E-49DF-ADAE-DD4C79FE0B57}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Faulty Device Manager Devices =============
 
Name: Microsoft Teredo Tunneling Adapter
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
Name: Security Processor Loader Driver
Description: Security Processor Loader Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: spldr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (09/23/2015 04:38:32 PM) (Source: AVLogEvent) (EventID: 5010) (User: NT AUTHORITY)
Description: McShield failed to start because it is not trusted.
Error Code:a7f40905
 
Error: (09/23/2015 04:38:32 PM) (Source: AVLogEvent) (EventID: 5007) (User: NT AUTHORITY)
Description: Failed to load a dependant module.
Error Code:a7f42003
 
Error: (09/23/2015 04:35:57 PM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file C:\Windows\Installer\7fe2385.msp for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program RogueKiller.exe because of this error.
 
Program: RogueKiller.exe
File: C:\Windows\Installer\7fe2385.msp
 
The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
- It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.
 
Additional Data
Error value: C000009C
Disk type: 3
 
Error: (09/23/2015 04:35:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: RogueKiller.exe, version: 10.10.6.0, time stamp: 0x55ffb25c
Faulting module name: RogueKiller.exe, version: 10.10.6.0, time stamp: 0x55ffb25c
Exception code: 0xc0000006
Fault offset: 0x006dd0d5
Faulting process id: 0xad4
Faulting application start time: 0xRogueKiller.exe0
Faulting application path: RogueKiller.exe1
Faulting module path: RogueKiller.exe2
Report Id: RogueKiller.exe3
 
Error: (09/23/2015 04:26:38 PM) (Source: AVLogEvent) (EventID: 5010) (User: NT AUTHORITY)
Description: McShield failed to start because it is not trusted.
Error Code:a7f40905
 
Error: (09/23/2015 04:26:38 PM) (Source: AVLogEvent) (EventID: 5007) (User: NT AUTHORITY)
Description: Failed to load a dependant module.
Error Code:a7f42003
 
Error: (09/23/2015 04:24:10 PM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file C:\Windows\Installer\7fe2385.msp for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program RogueKiller.exe because of this error.
 
Program: RogueKiller.exe
File: C:\Windows\Installer\7fe2385.msp
 
The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
- It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.
 
Additional Data
Error value: C000009C
Disk type: 3
 
Error: (09/23/2015 04:24:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: RogueKiller.exe, version: 10.10.6.0, time stamp: 0x55ffb25c
Faulting module name: RogueKiller.exe, version: 10.10.6.0, time stamp: 0x55ffb25c
Exception code: 0xc0000006
Fault offset: 0x006dd0d5
Faulting process id: 0xdfc
Faulting application start time: 0xRogueKiller.exe0
Faulting application path: RogueKiller.exe1
Faulting module path: RogueKiller.exe2
Report Id: RogueKiller.exe3
 
Error: (09/23/2015 04:12:44 PM) (Source: AVLogEvent) (EventID: 5010) (User: NT AUTHORITY)
Description: McShield failed to start because it is not trusted.
Error Code:a7f40905
 
Error: (09/23/2015 04:12:44 PM) (Source: AVLogEvent) (EventID: 5007) (User: NT AUTHORITY)
Description: Failed to load a dependant module.
Error Code:a7f42003
 
 
System errors:
=============
Error: (09/23/2015 10:00:01 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/23/2015 10:00:01 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/23/2015 10:00:01 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/23/2015 10:00:01 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/23/2015 10:00:01 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/23/2015 10:00:01 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/23/2015 10:00:01 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/23/2015 10:00:01 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/23/2015 10:00:01 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
Error: (09/23/2015 10:00:01 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
%%1068
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i5-4200U CPU @ 1.60GHz
Percentage of memory in use: 11%
Total physical RAM: 7833.11 MB
Available physical RAM: 6947.46 MB
Total Virtual: 15664.42 MB
Available Virtual: 14806.98 MB
 
==================== Drives ================================
 
Drive c: (Windows) (Fixed) (Total:451.31 GB) (Free:366.15 GB) NTFS
Drive d: (HP_RECOVERY) (Fixed) (Total:11.45 GB) (Free:1.27 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive e: (HP_TOOLS) (Fixed) (Total:1.99 GB) (Free:1.98 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 0FE3875A)
Partition 1: (Active) - (Size=1 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=451.3 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=11.4 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=2 GB) - (Type=0B)
 
==================== End of Addition.txt ============================
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:23-09-2015
Ran by [removed] (administrator) on SRELAB-HP (23-09-2015 22:00:31)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286056 2013-07-30] (Intel Corporation)
HKLM\…\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1703424 2013-07-04] (IDT, Inc.)
HKLM\…\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Broadcom\Broadcom 802.11\WLTRAY.exe [7032320 2013-09-30] (Broadcom Corporation)
HKLM\…\Run: [CryptoMill Refresh] => C:\Program Files\Hewlett-Packard\HP Trust Circles\ceflauncher -m refresh
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2774256 2013-08-19] (Synaptics Incorporated)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.)
HKLM-x32\…\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [683656 2013-07-18] (PDF Complete Inc)
HKLM-x32\…\Run: [HPConnectionManager] => c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe [185144 2013-08-15] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\…\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe [337184 2013-07-31] (Hewlett-Packard Company)
HKLM-x32\…\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation)
HKLM-x32\…\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [77088 2013-07-24] (Hewlett-Packard Company)
HKLM-x32\…\Run: [YouCam Mirage] => c:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488 2013-06-24] (CyberLink)
HKLM-x32\…\Run: [YouCam Tray] => c:\Program Files (x86)\CyberLink\YouCam\YouCamTray.exe [167488 2013-06-24] (CyberLink Corp.)
HKLM-x32\…\Run: [HP File Sanitizer] => C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\Coreshredder.exe [2213592 2013-08-07] (Hewlett-Packard)
HKLM-x32\…\Run: [mcpltui_exe] => C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe [719272 2015-04-02] (McAfee, Inc.)
HKLM\…\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe,
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\…\Policies\Explorer: [NoFolderOptions] 0
HKLM\…\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\…\Policies\Explorer: [NoDriveTypeAutoRun] 0xFF000000
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\…\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\…\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\…\MountPoints2: F - F:\LaunchU3.exe -a
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\…\MountPoints2: {076291c3-20cf-11e5-999e-24fd5220468b} - F:\LaunchU3.exe -a
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\…\MountPoints2: {f49b585e-3abe-11e4-bb22-24fd5220468b} - G:\Setup.exe
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [899584 2010-11-20] (Microsoft Corporation)
Lsa: [Notification Packages] DPPassFilter scecli c:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
ShellIconOverlayIdentifiers: [+1TBIcon] -> {B9C55E85-DED6-4911-82F3-83CF1CAB2898} => C:\Program Files\Hewlett-Packard\HP Trust Circles\tbicon.dll [2013-08-22] (CryptoMill Technologies Ltd.)
ShellIconOverlayIdentifiers-x32: [+1TBIcon] -> {B9C55E85-DED6-4911-82F3-83CF1CAB2898} => C:\Program Files (x86)\Hewlett-Packard\HP Trust Circles\tbicon.dll [2013-08-22] (CryptoMill Technologies Ltd.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2013-09-30]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ISCTSystray.lnk [2013-09-30]
ShortcutTarget: ISCTSystray.lnk -> C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe (Intel Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.150.1
Tcpip\..\Interfaces\{74926853-863F-4080-A8D2-B951833BED4F}: [DhcpNameServer] 192.168.150.1
Tcpip\..\Interfaces\{D98EC19B-EFC7-45D0-AE7E-E35FE2A78D92}: [DhcpNameServer] 192.168.150.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCOM14/1
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCOM14/1
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCOM14/1
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-08-12] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2014-01-21] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-07-14] (Microsoft Corporation)
BHO-x32: HP File Sanitizer -> {3134413B-49B4-425C-98A5-893C1F195601} -> C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll [2013-08-07] (Hewlett-Packard)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-08-12] (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2014-01-23] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-07-14] (Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2012-07-09] (Hewlett-Packard)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\program files\mcafee\msc\mcsniepl64.dll [2015-04-07] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\program files (x86)\mcafee\msc\mcsniepl.dll [2015-04-07] (McAfee, Inc.)
 
FireFox:
========
FF Plugin: @mcafee.com/MSC,version=10 -> c:\program files\mcafee\msc\npmcsnffpl64.dll [2015-04-07] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1215155.dll [2014-12-02] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-07-25] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-07-25] (Intel Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\program files (x86)\mcafee\msc\npmcsnffpl.dll [2015-04-07] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-03-31] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-28] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Plugin-x32: digitalpersona.com/ChromeDPAgent -> C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\ChromeExt\components\npChromeDPAgent.dll [2013-08-05] (DigitalPersona, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-03-31] (Microsoft Corporation)
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt
FF Extension: DigitalPersona Extension - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt [2013-09-30]
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://google.com/"
CHR Profile: C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-12]
CHR Extension: (Google Docs) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-12]
CHR Extension: (Google Drive) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-12]
CHR Extension: (YouTube) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-12]
CHR Extension: (Google Search) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-12]
CHR Extension: (Google Sheets) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-12]
CHR Extension: (Google Docs Offline) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-02]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13]
CHR Extension: (DigitalPersona Extension) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncffjdbbodifgldkcbhmiiljfcnbgjab [2014-09-12]
CHR Extension: (Chrome Web Store Payments) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-12]
CHR Extension: (Gmail) - C:\Users\SRE Lab\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-12]
CHR HKLM-x32\…\Chrome\Extension: [ncffjdbbodifgldkcbhmiiljfcnbgjab] - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\ChromeExt\dpchrome.crx [2013-08-05]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 0292761443040339mcinstcleanup; C:\Windows\TEMP\029276~1.EXE [883024 2015-04-06] () [File not signed]
S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
S2 CreoService; C:\Program Files (x86)\Hewlett-Packard\HP Trust Circles\CreoSvc.exe [1366488 2013-08-22] (CryptoMill Technologies Ltd.)
S2 CtAgentService; C:\Program Files (x86)\Hewlett-Packard\HP Theft Recovery\CtService.exe [7168 2013-08-07] () [File not signed]
S2 DpHost; C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe [500048 2013-08-05] (DigitalPersona, Inc.)
S3 FLCDLOCK; c:\Windows\SysWOW64\flcdlock.exe [558392 2013-08-06] (Hewlett-Packard Company)
S2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc.)
S2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-06-07] (Hewlett-Packard Company) [File not signed]
S2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe [681760 2013-07-31] (Hewlett-Packard Company)
S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [14696 2013-07-30] (Intel Corporation)
S2 Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
S2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-07-25] (Intel Corporation)
S2 ISCTAgent; c:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [197608 2013-07-22] ()
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-07-25] (Intel Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S4 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [753768 2015-04-07] (McAfee, Inc.)
S2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.5.450.0\McCSPServiceHost.exe [207344 2015-04-08] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc.)
S2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [612688 2015-04-09] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc.)
S2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc.)
S4 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [232656 2015-02-17] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [372144 2015-04-06] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [250672 2015-02-17] (McAfee, Inc.)
S2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1143432 2013-07-18] (PDF Complete Inc)
S2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [337920 2013-07-04] (IDT, Inc.) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
S2 wltrysvc; C:\Program Files\Broadcom\Broadcom 802.11\bcmwltry.exe [5878272 2013-09-30] (Broadcom Corporation) [File not signed]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [165688 2012-09-24] (Broadcom Corporation.)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [68784 2015-02-17] (McAfee, Inc.)
S3 DAMDrv; C:\Windows\System32\DRIVERS\DAMDrv64.sys [65752 2013-06-13] (Hewlett-Packard Company)
R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [488216 2014-02-28] (Intel Corporation)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [28008 2013-07-30] (Intel Corporation)
S3 IceKore; C:\Windows\System32\DRIVERS\IceKore.sys [397784 2013-08-19] (CryptoMill Technologies Inc.)
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [21408 2013-07-22] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [21920 2013-07-22] ()
S3 INETMON; C:\Windows\System32\Drivers\INETMON.sys [29088 2013-07-22] ()
R3 ISCT; C:\Windows\system32\drivers\ISCTD64.sys [46568 2013-07-22] ()
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-12-19] (Intel Corporation)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [401736 2015-02-17] (McAfee, Inc.)
S3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [337888 2015-02-17] (McAfee, Inc.)
R0 mfedisk; C:\Windows\System32\DRIVERS\mfedisk.sys [101872 2015-02-17] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [488000 2015-02-17] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [864072 2015-02-17] (McAfee, Inc.)
S3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [482600 2015-01-16] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [100720 2015-01-16] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [340448 2015-02-17] (McAfee, Inc.)
R0 PinFile; C:\Windows\System32\DRIVERS\PinFile.sys [49856 2013-07-16] (WinMagic Inc.)
S3 RTSPER; C:\Windows\System32\DRIVERS\RtsPer.sys [427736 2013-08-09] (Realsil Semiconductor Corporation)
R0 SDDisk2K; C:\Windows\System32\DRIVERS\SDDisk2K.sys [228544 2013-07-16] (WinMagic Inc.)
R0 SDDToki; C:\Windows\System32\DRIVERS\SDDToki.sys [131264 2013-07-16] (WinMagic Inc.)
S3 SmbDrv; C:\Windows\system32\drivers\Smb_driver_AMDASF.sys [30448 2013-08-19] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\system32\drivers\Smb_driver_Intel.sys [34544 2013-08-19] (Synaptics Incorporated)
S3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [1512568 2013-06-25] (Sunplus)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [35064 2015-09-23] ()
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-23 16:45 - 2015-09-23 16:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2015-09-23 16:19 - 2015-09-23 16:32 - 00035064 _____ C:\Windows\system32\Drivers\TrueSight.sys
2015-09-23 16:18 - 2015-09-23 16:18 - 00000000 ____D C:\ProgramData\RogueKiller
2015-09-23 16:17 - 2015-09-23 16:17 - 18801736 _____ C:\Users\SRE Lab\Desktop\RogueKiller.exe
2015-09-23 16:14 - 2015-09-23 16:16 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-09-23 16:14 - 2015-09-23 16:15 - 00000335 _____ C:\local.conf
2015-09-23 16:10 - 2015-09-23 16:16 - 00000000 ____D C:\Users\SRE Lab\Desktop\mbar
2015-09-23 16:09 - 2015-09-23 16:09 - 16563352 _____ (Malwarebytes Corp.) C:\Users\SRE Lab\Downloads\mbar-1.09.3.1001.exe
2015-09-23 13:38 - 2015-09-23 13:38 - 00000000 ____D C:\Program Files (x86)\ESET
2015-09-23 08:06 - 2015-09-23 08:06 - 00000000 ____D C:\Users\SRE Lab\Desktop\FRST-OlderVersion
2015-09-23 06:58 - 2015-09-23 06:58 - 06420480 _____ C:\Program Files (x86)\GUT69F9.tmp
2015-09-23 06:58 - 2015-09-23 06:58 - 00000000 ____D C:\Program Files (x86)\GUM69F8.tmp
2015-09-21 22:20 - 2015-09-21 22:20 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\SRE Lab\Desktop\mbam-setup-2.1.8.1057 (2).exe
2015-09-21 22:18 - 2015-09-21 22:18 - 00001221 _____ C:\Users\SRE Lab\Desktop\JRT.txt
2015-09-21 22:15 - 2015-09-21 22:15 - 01798976 _____ (Malwarebytes) C:\Users\SRE Lab\Desktop\JRT.exe
2015-09-21 22:05 - 2015-09-21 22:09 - 00000000 ____D C:\AdwCleaner
2015-09-21 22:03 - 2015-09-21 22:03 - 01662976 _____ C:\Users\SRE Lab\Downloads\AdwCleaner.exe
2015-09-18 11:16 - 2015-09-23 22:00 - 00020760 _____ C:\Users\SRE Lab\Desktop\FRST.txt
2015-09-18 11:16 - 2015-09-22 20:40 - 00030727 _____ C:\Users\SRE Lab\Desktop\Addition.txt
2015-09-18 11:15 - 2015-09-23 22:00 - 00000000 ____D C:\FRST
2015-09-18 11:09 - 2015-09-23 08:06 - 02192384 _____ (Farbar) C:\Users\SRE Lab\Desktop\FRST64.exe
2015-09-18 11:07 - 2015-09-18 11:07 - 00002306 _____ C:\Users\SRE Lab\Desktop\aswMBR.txt
2015-09-18 11:07 - 2015-09-18 11:07 - 00000512 _____ C:\Users\SRE Lab\Desktop\MBR.dat
2015-09-18 10:54 - 2015-09-18 10:55 - 05198336 _____ (AVAST Software) C:\Users\SRE Lab\Desktop\aswMBR.exe
2015-09-13 19:36 - 2015-09-23 16:14 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-09-13 19:35 - 2015-09-23 16:13 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-09-13 19:35 - 2015-09-21 22:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-09-13 19:35 - 2015-09-21 22:21 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-09-13 19:35 - 2015-09-13 19:35 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-09-13 19:35 - 2015-06-18 08:41 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-09-13 19:35 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-09-13 19:32 - 2015-09-13 19:34 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\SRE Lab\Downloads\mbam-setup-2.1.8.1057 (1).exe
2015-09-13 19:32 - 2015-09-13 19:33 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\SRE Lab\Downloads\mbam-setup-2.1.8.1057.exe
2015-09-13 18:43 - 2015-09-13 18:43 - 00003280 ____N C:\bootsqm.dat
2015-09-10 08:24 - 2015-09-10 08:24 - 00010731 _____ C:\Users\SRE Lab\Downloads\meeting.collab
2015-09-10 08:24 - 2015-09-10 08:24 - 00010731 _____ C:\Users\SRE Lab\Downloads\meeting (1).collab
2015-09-09 23:48 - 2015-09-09 23:48 - 00008432 _____ C:\Users\SRE Lab\Downloads\work_room (1).collab
2015-09-09 23:45 - 2015-09-09 23:46 - 00000000 ____D C:\Users\SRE Lab\AppData\Roaming\Blackboard
2015-09-09 23:39 - 2015-09-09 23:39 - 00000000 ____D C:\Users\SRE Lab\AppData\Local\Blackboard
2015-09-09 15:19 - 2015-08-17 18:42 - 00393304 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-09-09 15:19 - 2015-08-17 18:14 - 00344168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-09-09 15:19 - 2015-08-14 23:48 - 25190400 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-09-09 15:19 - 2015-08-14 23:34 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-09-09 15:19 - 2015-08-14 23:33 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-09-09 15:19 - 2015-08-14 23:18 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-09-09 15:19 - 2015-08-14 23:18 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-09-09 15:19 - 2015-08-14 23:17 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-09-09 15:19 - 2015-08-14 23:17 - 00585216 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-09-09 15:19 - 2015-08-14 23:17 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-09-09 15:19 - 2015-08-14 23:17 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-09-09 15:19 - 2015-08-14 23:10 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-09-09 15:19 - 2015-08-14 23:09 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-09-09 15:19 - 2015-08-14 23:06 - 19856896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-09-09 15:19 - 2015-08-14 23:06 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-09-09 15:19 - 2015-08-14 23:04 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-09-09 15:19 - 2015-08-14 23:04 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-09-09 15:19 - 2015-08-14 23:04 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-09-09 15:19 - 2015-08-14 23:04 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-09-09 15:19 - 2015-08-14 23:00 - 05923328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-09-09 15:19 - 2015-08-14 22:57 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-09-09 15:19 - 2015-08-14 22:53 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-09-09 15:19 - 2015-08-14 22:53 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-09-09 15:19 - 2015-08-14 22:46 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-09-09 15:19 - 2015-08-14 22:42 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-09-09 15:19 - 2015-08-14 22:41 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-09-09 15:19 - 2015-08-14 22:40 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-09-09 15:19 - 2015-08-14 22:40 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-09-09 15:19 - 2015-08-14 22:39 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-09-09 15:19 - 2015-08-14 22:39 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-09-09 15:19 - 2015-08-14 22:39 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-09-09 15:19 - 2015-08-14 22:38 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-09-09 15:19 - 2015-08-14 22:35 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-09-09 15:19 - 2015-08-14 22:33 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-09-09 15:19 - 2015-08-14 22:32 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-09-09 15:19 - 2015-08-14 22:30 - 00479232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-09-09 15:19 - 2015-08-14 22:29 - 00665600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-09-09 15:19 - 2015-08-14 22:29 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-09-09 15:19 - 2015-08-14 22:29 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-09-09 15:19 - 2015-08-14 22:24 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-09-09 15:19 - 2015-08-14 22:23 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-09-09 15:19 - 2015-08-14 22:22 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-09-09 15:19 - 2015-08-14 22:22 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-09-09 15:19 - 2015-08-14 22:21 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-09-09 15:19 - 2015-08-14 22:16 - 14451712 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-09-09 15:19 - 2015-08-14 22:16 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-09-09 15:19 - 2015-08-14 22:14 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-09-09 15:19 - 2015-08-14 22:12 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-09-09 15:19 - 2015-08-14 22:11 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-09-09 15:19 - 2015-08-14 22:10 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-09-09 15:19 - 2015-08-14 22:07 - 02427392 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-09-09 15:19 - 2015-08-14 22:04 - 12857344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-09-09 15:19 - 2015-08-14 22:02 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-09-09 15:19 - 2015-08-14 22:01 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-09-09 15:19 - 2015-08-14 22:01 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-09-09 15:19 - 2015-08-14 21:55 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-09-09 15:19 - 2015-08-14 21:43 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-09-09 15:19 - 2015-08-14 21:43 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-09-09 15:19 - 2015-08-14 21:39 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-09-09 15:19 - 2015-08-14 21:37 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-09-09 15:19 - 2015-08-05 10:56 - 01110016 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2015-09-09 15:19 - 2015-07-14 20:17 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2015-09-09 15:19 - 2015-07-14 19:54 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2015-09-09 15:19 - 2015-07-09 10:58 - 01632256 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-09-09 15:19 - 2015-07-09 10:58 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2015-09-09 15:19 - 2015-07-09 10:42 - 01372160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-09-09 15:19 - 2015-07-09 10:42 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2015-09-09 15:14 - 2015-08-27 11:18 - 02004480 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-09-09 15:14 - 2015-08-27 11:18 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-09-09 15:14 - 2015-08-27 11:13 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2015-09-09 15:14 - 2015-08-27 11:13 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-09-09 15:14 - 2015-08-27 10:58 - 01391104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2015-09-09 15:14 - 2015-08-27 10:58 - 01241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-09-09 15:14 - 2015-08-27 10:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2015-09-09 15:14 - 2015-08-27 10:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2015-09-09 15:14 - 2015-06-25 03:06 - 00115136 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-09-09 15:14 - 2015-06-25 03:01 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-09-09 15:14 - 2015-06-25 03:01 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2015-09-09 15:14 - 2015-06-25 02:44 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-09-09 15:13 - 2015-09-01 20:04 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-09-09 15:13 - 2015-09-01 20:04 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-09-09 15:13 - 2015-09-01 20:04 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-09-09 15:13 - 2015-09-01 20:04 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-09-09 15:13 - 2015-09-01 19:48 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2015-09-09 15:13 - 2015-09-01 19:48 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-09-09 15:13 - 2015-09-01 19:48 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2015-09-09 15:13 - 2015-09-01 19:47 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2015-09-09 15:13 - 2015-09-01 18:51 - 03209216 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-09-09 15:13 - 2015-09-01 18:47 - 00372736 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-09-09 15:13 - 2015-09-01 18:33 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-09-09 15:12 - 2015-08-26 11:07 - 03165696 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-09-09 15:12 - 2015-08-26 11:07 - 02606080 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-09-09 15:12 - 2015-08-26 11:07 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-09-09 15:12 - 2015-08-26 11:07 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-09-09 15:12 - 2015-08-26 11:07 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-09-09 15:12 - 2015-08-26 11:07 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-09-09 15:12 - 2015-08-26 11:07 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-09-09 15:12 - 2015-08-26 11:06 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-09-09 15:12 - 2015-08-26 11:06 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-09-09 15:12 - 2015-08-26 11:06 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-09-09 15:12 - 2015-08-26 11:06 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-09-09 15:12 - 2015-08-26 10:56 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-09-09 15:12 - 2015-08-26 10:56 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-09-09 15:12 - 2015-08-26 10:56 - 00093184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-09-09 15:12 - 2015-08-26 10:56 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2015-09-09 15:12 - 2015-08-26 10:55 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-09-06 12:53 - 2015-09-06 12:54 - 25482411 _____ C:\Users\SRE Lab\Desktop\The infiltrator.mp4
2015-09-01 13:50 - 2015-09-01 13:50 - 00002095 _____ C:\Users\Public\Desktop\Zoo Tycoon.lnk
2015-09-01 13:50 - 2015-09-01 13:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
2015-09-01 13:33 - 2015-09-01 13:33 - 00001336 _____ C:\Users\SRE Lab\Desktop\LEGO Racers.lnk
2015-08-31 15:16 - 2015-09-01 12:59 - 00000000 ____D C:\Users\SRE Lab\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-08-31 15:07 - 2015-08-31 15:07 - 00000000 ____D C:\Program Files (x86)\Microsoft Games
2015-08-27 16:15 - 2015-08-27 16:16 - 00271113 _____ C:\Users\SRE Lab\Downloads\pac-man.zip
2015-08-27 13:12 - 2015-08-27 13:13 - 20822282 _____ C:\Users\SRE Lab\Desktop\THe Trashie strongarm.mp4
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-23 16:40 - 2009-07-13 22:13 - 00805950 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-23 09:18 - 2009-07-13 21:45 - 00026832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-09-23 09:16 - 2009-07-13 21:45 - 00026832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-09-23 09:08 - 2013-10-24 10:28 - 01333661 _____ C:\Windows\WindowsUpdate.log
2015-09-23 09:05 - 2014-09-14 19:38 - 00000000 ____D C:\Program Files (x86)\McAfee
2015-09-23 08:59 - 2013-09-08 21:35 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-09-23 08:59 - 2013-09-08 21:35 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-09-23 08:43 - 2014-09-12 10:03 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-23 08:30 - 2013-09-08 21:35 - 00000000 ____D C:\ProgramData\PDFC
2015-09-23 08:28 - 2014-09-12 10:03 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-23 08:28 - 2013-09-30 10:13 - 00000225 _____ C:\Windows\CryptoMill_CreoService.log
2015-09-23 08:28 - 2009-07-13 22:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-23 08:28 - 2009-07-13 21:51 - 00114282 _____ C:\Windows\setupact.log
2015-09-23 08:07 - 2013-09-30 10:13 - 00000225 _____ C:\Windows\CryptoMill_CreoService.001
2015-09-23 08:00 - 2013-09-30 10:13 - 00000225 _____ C:\Windows\CryptoMill_CreoService.002
2015-09-23 07:28 - 2013-10-24 10:27 - 00003938 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{DD9B90AE-3AD8-4A15-A8BB-9A1EB32D171F}
2015-09-23 07:08 - 2013-09-30 10:13 - 00000225 _____ C:\Windows\CryptoMill_CreoService.003
2015-09-23 06:41 - 2013-09-30 10:13 - 00000225 _____ C:\Windows\CryptoMill_CreoService.004
2015-09-22 20:43 - 2013-09-30 10:13 - 00000225 _____ C:\Windows\CryptoMill_CreoService.005
2015-09-21 22:09 - 2009-07-13 20:20 - 00000000 ____D C:\Program Files\Common Files\System
2015-09-14 06:53 - 2009-07-13 21:45 - 00433064 _____ C:\Windows\system32\FNTCACHE.DAT
2015-09-14 06:51 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-09-14 06:35 - 2014-09-12 11:24 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-09-14 06:35 - 2014-09-12 11:20 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-09-14 06:33 - 2014-09-11 13:39 - 00000000 ____D C:\Windows\system32\MRT
2015-09-14 06:25 - 2009-07-13 19:34 - 00000580 _____ C:\Windows\win.ini
2015-09-13 20:25 - 2010-11-20 20:47 - 00317134 _____ C:\Windows\PFRO.log
2015-09-13 19:17 - 2015-07-25 10:07 - 00000000 ____D C:\Users\SRE Lab\AppData\Local\Unity
2015-09-13 19:16 - 2014-09-12 06:29 - 00000000 ____D C:\Windows\system32\appmgmt
2015-09-13 18:39 - 2015-02-28 21:43 - 00000000 ____D C:\Users\SRE Lab\AppData\Local\Intel_Corporation
2015-09-13 14:54 - 2014-09-14 15:54 - 00000000 ____D C:\Users\SRE Lab\AppData\Local\CrashDumps
2015-09-11 11:44 - 2014-10-13 20:30 - 00000000 ____D C:\Users\SRE Lab\Documents\Outlook Files
2015-09-10 16:46 - 2014-09-12 10:03 - 00000000 ____D C:\Users\SRE Lab\AppData\Local\Google
2015-09-06 13:57 - 2015-05-16 17:11 - 00000000 ____D C:\Users\SRE Lab\Desktop\Dawn Of War
2015-09-05 18:30 - 2015-07-14 13:37 - 00028222 _____ C:\Users\SRE Lab\Documents\The Stealthy Sniper.wlmp
2015-08-28 10:38 - 2014-09-12 10:03 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-08-28 10:38 - 2014-09-12 10:03 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-08-27 15:47 - 2014-09-16 20:50 - 00000000 ____D C:\Python32
2015-08-26 18:37 - 2014-09-11 13:39 - 134753440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
 
==================== Files in the root of some directories =======
 
2015-09-23 06:58 - 2015-09-23 06:58 - 6420480 _____ () C:\Program Files (x86)\GUT69F9.tmp
2014-09-14 15:04 - 2014-09-14 15:04 - 0000044 _____ () C:\Users\SRE Lab\AppData\Roaming\WB.CFG
 
Some files in TEMP:
====================
C:\Users\SRE Lab\AppData\Local\Temp\dllnt_dump.dll
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-09-01 08:40
 
==================== End of FRST.txt ============================
 

Lets fix these and see if it helps

 

Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist, Save it to your desktop where you have FRST/FRST64 or the fix wont work, . Then open up FRST/FRST64 and click on FIX (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
 

Start
CloseProcesses:
CreateRestorePoint: 
HKLM\…\Policies\Explorer: [NoFolderOptions] 0
HKLM\…\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\…\Policies\Explorer: [NoDriveTypeAutoRun] 0xFF000000
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\…\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-21-2887876563-769068690-2455426777-1001\…\Policies\Explorer: [NoControlPanel] 0
Hosts:
CMD: ipconfig /flushdns
EmptyTemp:
End
 
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
 
 
 
 
 
Then lets run System File Checker to see if any windows files are missing or corrupt
 
 
 

 
Click on  Start - All Programs - Accessories - Right click Command Prompt and choose Run As Administrator. Type (or copy and paste by right clicking in the Command Prompt window and choosing Paste). Then press Enter on your keyboard
 
sfc /scannow
 
 
A report wont pop up, the program will just close when its done
 
To find the  SFC Results go to Start - All Programs - Accessories - Right click Command Prompt and choose Run As Administrator. Type (or copy and paste by right clicking in the Command Prompt window and choosing Paste). Then press Enter on your keyboard
 
 
findstr /c:"[SR] Cannot" %windir%\logs\cbs\cbs.log|more
 
 
 
 
 

 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI